Home / Security / Advisories / NTAP-20210315-0001
NTAP-20210315-0001 — CVE-2021-26987 SpringBoot Framework Remote Code Execution Vulnerability in Management Software for Element Software and NetApp HCI
Published 2021-03-15 · Updated 2022-06-29 · Status: Final · Exploitation: Public · Severity: not scored · ONTAP affected: No — other NetApp product
Product family: Other NetApp products · SolidFire / NetApp HCI | other NetApp product
CVEs in this advisory
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). <br><br> In order to upgrade to a fixed version of Management Services the storage cluster must be running NetApp Element software and management node version 11.3 or later. <br><br> For existing vSphere environments with a registered NetApp Element Plug-in for vCenter Server (VCP), update the plug-in registration after updating the management services package by following these instructions: <a href="https://docs.netapp.com/us-en/hci/docs/task_vcp_upgrade_plugin.html">https://docs.netapp.com/us-en/hci/docs/task_vcp_upgrade_plugin.html</a> <br><br> If the storage cluster and management node are running versions prior to Element Software 11.3, please contact NetApp Support to schedule an upgrade.
Affected products
- Element Plug-in for vCenter Server
- Management Services for Element Software and NetApp HCI
- NetApp SolidFire & HCI Management Node
Official fixes
- NetApp SolidFire & HCI Management Node — vendor fix ↗
- Element Plug-in for vCenter Server — vendor fix ↗
- Management Services for Element Software and NetApp HCI — vendor fix ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2021