Home / Security / Advisories / NTAP-20191210-0001
NTAP-20191210-0001 — CVE-2019-1551 OpenSSL Vulnerability in NetApp Products
Published 2019-12-10 · Updated 2024-03-07 · Status: Final · Exploitation: Public · Severity: MEDIUM 5.3 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · Baseboard management controllers · Cloud Backup / AltaVault / SteelStore · E-Series / SANtricity · Other NetApp products · SolidFire / NetApp HCI · ONTAP · OnCommand family · SnapManager / Snap utilities | ONTAP-relevant | highest CVSS: 5.3
CVEs in this advisory
- CVE-2019-1551 — MEDIUM · CVSS 5.3 · site index
What the CVE records say
CVE-2019-1551 — There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information.
Affected products
- Active IQ Unified Manager for VMware vSphere
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
- NetApp Cloud Backup (formerly AltaVault)
- NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)
- NetApp E-Series Performance Analyzer
- NetApp Plug-in for Symantec NetBackup
- NetApp SANtricity SMI-S Provider
- NetApp SMI-S Provider
- NetApp SolidFire Baseboard Management Controller (BMC)
- NetApp SteelStore Cloud Integrated Storage
- ONTAP Antivirus Connector
- ONTAP Select Deploy administration utility
Official fixes
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- ONTAP Antivirus Connector — vendor fix ↗
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400 — vendor fix ↗
- NetApp E-Series Performance Analyzer — vendor fix ↗
- NetApp SANtricity SMI-S Provider — vendor fix ↗
- NetApp SMI-S Provider — vendor fix ↗
- OnCommand Unified Manager Core Package — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- ONTAP Select Deploy administration utility — vendor fix ↗
- SnapDrive for Unix — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2019