Home / Security / Advisories / NTAP-20200413-0001
NTAP-20200413-0001 — March 2020 FreeBSD Vulnerabilities in NetApp Products
Published 2020-04-13 · Updated 2021-01-15 · Status: Final · Exploitation: Public · Severity: CRITICAL 9.1 · ONTAP affected: Yes
Product family: ONTAP | ONTAP-relevant | highest CVSS: 9.1
CVEs in this advisory
- CVE-2019-15876 — MEDIUM · CVSS 5.5 · site index
- CVE-2019-15877 — MEDIUM · CVSS 5.5 · site index
- CVE-2020-7451 — MEDIUM · CVSS 5.3 · site index
- CVE-2020-7452 — CRITICAL · CVSS 9.1 · site index
- CVE-2020-7453 — MEDIUM · CVSS 6.0 · site index
What the CVE records say
CVE-2019-15876 — In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough commands to the device firmware.
CVE-2019-15877 — In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory.
CVE-2020-7451 — In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TCP SYN-ACK or challenge TCP-ACK segment over IPv6 that is transmitted or retransmitted does not properly initialize the Traffic Class field disclosing one byte of kernel memory over the network.
CVE-2020-7452 — In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary code in the kernel.
CVE-2020-7453 — In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail superuser with permission to create nested jails to read kernel memory.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). <br><br> Clustered Data ONTAP is affected only by CVE-2020-7451.
Affected products
- Clustered Data ONTAP
- Data ONTAP operating in 7-Mode
Official fixes
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Data ONTAP operating in 7-Mode — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2020