Home / Security / Advisories / NTAP-20180926-0001
NTAP-20180926-0001 — June 2017 ISC BIND Vulnerabilities in NetApp Products
Published 2018-09-26 · Updated 2018-12-11 · Status: Final · Exploitation: Public · Severity: HIGH 7.2 · ONTAP affected: Yes
Product family: ONTAP · SolidFire / NetApp HCI · OnCommand family | ONTAP-relevant | highest CVSS: 7.2
CVEs in this advisory
- CVE-2017-3140 — LOW · CVSS 3.7 · site index
- CVE-2017-3141 — HIGH · CVSS 7.2 · site index
What the CVE records say
CVE-2017-3140 — If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
CVE-2017-3141 — The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
Impact
Successful exploitation of these vulnerabilities could lead to privilege escalation, disclosure of sensistive information, or Denial of Service (DoS).
Affected products
- Data ONTAP Edge
- NetApp SolidFire & HCI Storage Node (Element Software)
- OnCommand Balance
Official fixes
- NetApp SolidFire & HCI Storage Node (Element Software) — vendor fix ↗
References
- https://kb.isc.org/category/74/0/10/Software-Products/BIND9/Security-Advisories/ ↗
- https://kb.isc.org/article/AA-01497 ↗
- https://kb.isc.org/article/AA-01495/74/CVE-2017-3140 ↗
- https://kb.isc.org/article/AA-01496/74/CVE-2017-3141 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2018