Home / Security / Advisories / NTAP-20180330-0002
NTAP-20180330-0002 — March 2018 OpenSSL Vulnerabilities in NetApp Products
Published 2018-03-30 · Updated 2021-04-09 · Status: Final · Exploitation: Public · Severity: MEDIUM 6.5 · ONTAP affected: Yes
Product family: Other NetApp products · ONTAP · Cloud Backup / AltaVault / SteelStore · OnCommand family · SnapCenter · SnapManager / Snap utilities | ONTAP-relevant | highest CVSS: 6.5
CVEs in this advisory
- CVE-2018-0739 — MEDIUM · CVSS 6.5 · site index
- CVE-2018-0733 — MEDIUM · CVSS 5.9 · site index
What the CVE records say
CVE-2018-0739 — Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).
CVE-2018-0733 — Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX assembler, so that only HP-UX PA-RISC targets are affected. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g).
Impact
Successful exploitation of these vulnerabilities could lead to unauthorized addition or modification of data or a Denial of Service (DoS).
Affected products
- Cluster Network Switch (NetApp CN1610)
- Clustered Data ONTAP Antivirus Connector
- Data ONTAP Edge
- Data ONTAP operating in 7-Mode
- NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)
- NetApp Host Agent
- NetApp Plug-in for Symantec NetBackup
- NetApp SMI-S Provider
- NetApp VASA Provider for Clustered Data ONTAP 9.6 and above
- ONTAP Select Deploy administration utility
- OnCommand Workflow Automation
- SnapCenter
Official fixes
- ONTAP Select Deploy administration utility — vendor fix ↗
- SnapDrive for Unix — vendor fix ↗
- SnapDrive for Windows — vendor fix ↗
- NetApp SMI-S Provider — vendor fix ↗
- Virtual Storage Console for VMware vSphere 9.6 and above — vendor fix ↗
- Data ONTAP operating in 7-Mode — vendor fix ↗
- NetApp VASA Provider for Clustered Data ONTAP 9.6 and above — vendor fix ↗
- NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in) — vendor fix ↗
- Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.6 and above — vendor fix ↗
- SnapCenter — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2018