Home / Security / Advisories / NTAP-20180104-0001

NTAP-20180104-0001 — Processor Speculated Execution Vulnerabilities in NetApp Products

Published 2018-01-04 · Updated 2020-06-12 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product

Official advisory: NTAP-20180104-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: SolidFire / NetApp HCI  |  other NetApp product

CVEs in this advisory

Impact

Successful exploitation of these vulnerabilities allows unprivileged attackers to abuse CPU data cache timing to leak information out of speculated execution, potentially leading to the arbitrary read of virtual memory across local security boundaries via targeted attacks. These attacks require the ability to run malicious code directly on the target system. <br><br> ONTAP:<br> Unlike a general-purpose operating system, ONTAP does not provide mechanisms for non-administrative users to run third-party code. Due to this behavior, ONTAP is not affected by either the Spectre or Meltdown attacks. The same is true of all ONTAP variants including both ONTAP running on FAS/AFF hardware as well as virtualized ONTAP products such as ONTAP Select and ONTAP Cloud. <br><br> While ONTAP Select and ONTAP Cloud are not directly affected by these attacks, these attacks may be possible against the utilized hypervisor platform. NetApp recommends working with your hypervisor and cloud platform vendors to ensure that your NetApp product is running on a secure and patched platform. <br><br> StorageGRID:<br> StorageGRID and StorageGRID Webscale do not provide mechanisms for running unprivileged third-party code and are not directly affected. For virtualized deployments, NetApp recommends working with your hypervisor and cloud platform vendors to ensure that your NetApp product is running on a secure and patched platform. For Docker-based deployments, NetApp recommends working with your operating system and hardware vendors to ensure that your NetApp product is running on a secure and patched platform. <br><br> NetApp HCI Storage Nodes:<br> Unlike a general-purpose operating system, Element OS is a closed system that does not provide mechanisms for running third-party code. Due to this behavior, Element OS running on SolidFire or NetApp HCI Storage nodes is not affected by either the Spectre or Meltdown attacks as they depend on the ability to run malicious code directly on the target system. <br><br> SANtricity:<br> Unlike a general-purpose operating system, SANtricity does not provide mechanisms for running third-party code. Due to this behavior, SANtricity is not affected by either the Spectre or Meltdown attacks as they depend on the ability to run malicious code directly on the target system. <br><br> OnCommand Unified Manager for VMware vSphere: <br> OnCommand Unified Manager for VMware vSphere packages Unified Manager into a VMware hypervisor environment and does not provide mechanisms for non-administrative users to run third-party code on the hypervisor. Due to this behavior, OnCommand Unified Manager for VMware vSphere is not affected by either the Spectre or Meltdown attacks. <br><br> While OnCommand Unified Manager for VMware vSphere is not directly affected by these attacks, these attacks may be possible against the utilized hypervisor platform. NetApp recommends working with your hypervisor and cloud platform vendors to ensure that your NetApp product is running on a secure and patched platform. <br><br> Brocade Advisory: <br> <a href="http://www.brocade.com/content/dam/common/documents/content-types/security-bulletin/brocade-security-advisory-2018-522.htm">http://www.brocade.com/content/dam/common/documents/content-types/security-bulletin/brocade-security-advisory-2018-522.htm</a> <br><br> FAS/AFF System Firmware (BIOS): <br> FAS/AFF BIOS firmware does not provide a mechanism to run arbitrary code and thus is not susceptible to either the Spectre or Meltdown attacks. <br><br> NetApp HCI Compute Node (Bootstrap OS):<br> NetApp HCI Compute Node is tracked as affected with remediation by customer installation of ESXi patches and microcode updates from VMware detailed in <a href="https://kb.vmware.com/s/article/52245">KB 52245</a>. <br><br> NetApp SolidFire & HCI Management Node:<br> The NetApp SolidFire Element OS Management Node provides console access for end users and therefore it is tracked as affected. The underlying hypervisor infrastructure should be patched by customer installation of ESXi patches and microcode updates. Customers running whitebox server should consult the manufacturer for microcode availability.

Affected products

Official fixes

References

What to do

  1. Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
  2. Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
  3. Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
  4. Track follow-ups in the site CVE index and the security RSS feed.

Related reading

Browse all ONTAP CVEs → · Security hub