Home / Security / Advisories / NTAP-20191210-0001

NTAP-20191210-0001 — CVE-2019-1551 OpenSSL Vulnerability in NetApp Products

Published 2019-12-10 · Updated 2024-03-07 · Status: Final · Exploitation: Public · Severity: MEDIUM 5.3 · ONTAP affected: Yes

Official advisory: NTAP-20191210-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Active IQ Unified Manager · Baseboard management controllers · Cloud Backup / AltaVault / SteelStore · E-Series / SANtricity · Other NetApp products · SolidFire / NetApp HCI · ONTAP · OnCommand family · SnapManager / Snap utilities  |  ONTAP-relevant  |  highest CVSS: 5.3

CVEs in this advisory

What the CVE records say

CVE-2019-1551 — There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasible. However, for an attack the target would have to re-use the DH512 private key, which is not recommended anyway. Also applications directly using the low level API BN_mod_exp may be affected if they use BN_FLG_CONSTTIME. Fixed in OpenSSL 1.1.1e (Affected 1.1.1-1.1.1d). Fixed in OpenSSL 1.0.2u (Affected 1.0.2-1.0.2t).

Impact

Successful exploitation of this vulnerability could lead to disclosure of sensitive information.

Affected products

Official fixes

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub