Home / Security / Advisories / NTAP-20180802-0002
NTAP-20180802-0002 — April 2017 ISC BIND Vulnerabilities in NetApp Products
Published 2018-08-02 · Updated 2018-12-11 · Status: Final · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: ONTAP · SolidFire / NetApp HCI · OnCommand family | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2017-3136 — MEDIUM · CVSS 5.9 · site index
- CVE-2017-3137 — HIGH · CVSS 7.5 · site index
- CVE-2017-3138 — MEDIUM · CVSS 6.5 · site index
What the CVE records say
CVE-2017-3136 — A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S8.
CVE-2017-3137 — Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0-P3, 9.11.1b1->9.11.1rc1, and 9.9.9-S8.
CVE-2017-3138 — named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent a null command string. Affects BIND 9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S9.
Impact
Successful exploitation of these vulnerabilities may result in Denial of Service (DoS).
Affected products
- Data ONTAP Edge
- NetApp SolidFire & HCI Storage Node (Element Software)
- OnCommand Balance
Official fixes
- NetApp SolidFire & HCI Storage Node (Element Software) — vendor fix ↗
References
- https://kb.isc.org/article/AA-01465/74/CVE-2017-3136 ↗
- https://kb.isc.org/article/AA-01466/74/CVE-2017-3137 ↗
- https://kb.isc.org/article/AA-01471/74/CVE-2017-3138 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2018