Home / Security / Advisories / NTAP-20190809-0002

NTAP-20190809-0002 — CVE-2019-1125 SWAPGS Speculative Execution Side Channel Vulnerability in NetApp Products

Published 2019-08-09 · Updated 2024-03-07 · Status: Final · Exploitation: Public · Severity: MEDIUM 5.6 · ONTAP affected: Yes

Official advisory: NTAP-20190809-0002 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Active IQ Unified Manager · Cloud Backup / AltaVault / SteelStore · SolidFire / NetApp HCI · ONTAP  |  ONTAP-relevant  |  highest CVSS: 5.6

CVEs in this advisory

What the CVE records say

CVE-2019-1125 — An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and run a specially crafted application. The vulnerability would not allow an attacker to elevate user rights directly, but it could be used to obtain information that could be used to try to compromise the affected system further. On January 3, 2018, Microsoft released an advisory and security updates related to a newly-discovered class of hardware vulnerabilities (known as Spectre) involving speculative execution side channels that affect AMD, ARM, and Intel CPUs to varying degrees. This vulnerability, released on August 6, 2019, is a variant of the Spectre Variant 1 speculative execution side channel vulnerability and has been assigned CVE-2019-1125. Microsoft released a security update on July 9, 2019 that addresses the vulnerability through a software change that mitigates how the CPU speculatively accesses memory. Note that this vulnerability does not require a microcode update from your device OEM.

Impact

Successful exploitation of this vulnerability could lead to unauthorized disclosure of sensitive information. <br><br> StorageGRID:<br> StorageGRID and StorageGRID Webscale do not provide mechanisms for running unprivileged third-party code and are not directly affected. For virtualized deployments, NetApp recommends working with your hypervisor and cloud platform vendors to ensure that your NetApp product is running on a secure and patched platform. For Docker-based deployments, NetApp recommends working with your operating system and hardware vendors to ensure that your NetApp product is running on a secure and patched platform. <br><br> SANtricity:<br> Unlike a general-purpose operating system, SANtricity does not provide mechanisms for running third-party code. Due to this behavior, SANtricity is not affected by the SWAPGS attack as it depends on the ability to run malicious code directly on the target system. <br><br> Element Software:<br> Unlike a general-purpose operating system, Element OS is a closed system that does not provide mechanisms for running third-party code. Due to this behavior, Element OS running on SolidFire or NetApp HCI nodes is not affected by the SWAPGS attack due to the need to run malicious code directly on the target system <br><br> Element Software Management Node:<br> The NetApp SolidFire Element OS Management Node provides console access for end users and therefore it is tracked as affected. The underlying hypervisor infrastructure should be patched by customer installation of ESXi patches and microcode updates. Customers running whitebox server should consult the manufacturer for microcode availability.

Affected products

Official fixes

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub