Home / Security / Advisories / NTAP-20230420-0010
NTAP-20230420-0010 — March 2023 cURL/libcURL Vulnerabilities in NetApp Products
Published 2023-04-20 · Updated 2026-06-08 · Status: Interim · Exploitation: Public · Severity: MEDIUM 5.9 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · Brocade SAN firmware · SolidFire / NetApp HCI · ONTAP | ONTAP-relevant | highest CVSS: 5.9
CVEs in this advisory
- CVE-2023-27535 — MEDIUM · CVSS 5.9 · site index
- CVE-2023-27536 — MEDIUM · CVSS 5.9 · site index
- CVE-2023-27537 — MEDIUM · CVSS 5.9 · site index
- CVE-2023-27538 — MEDIUM · CVSS 5.5 · site index
What the CVE records say
CVE-2023-27535 — An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current setup. However, certain FTP settings such as CURLOPT_FTP_ACCOUNT, CURLOPT_FTP_ALTERNATIVE_TO_USER, CURLOPT_FTP_SSL_CCC, and CURLOPT_USE_SSL were not included in the configuration match checks, causing them to match too easily. This could lead to libcurl using the wrong credentials when performing a transfer, potentially allowing unauthorized access to sensitive information.
CVE-2023-27536 — An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability affects krb5/kerberos/negotiate/GSSAPI transfers and could potentially result in unauthorized access to sensitive information. The safest option is to not reuse connections if the CURLOPT_GSSAPI_DELEGATION option has been changed.
CVE-2023-27537 — A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
CVE-2023-27538 — An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two SSH settings were omitted from the configuration check, allowing them to match easily, potentially leading to the reuse of an inappropriate connection.
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or Denial of Service (DoS). <br><br> Active IQ Unified Manager for VMware vSphere:<br> Affected by only CVE-2023-27535 and CVE-2023-27536 in all supported versions.
Affected products
- Active IQ Unified Manager for VMware vSphere
- Brocade Fabric Operating System Firmware
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
- NetApp HCI Compute Node (Bootstrap OS)
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- ONTAP 9
Official fixes
- ONTAP 9 — vendor fix ↗
- ONTAP 9 — vendor fix ↗
- ONTAP 9 — vendor fix ↗
- ONTAP 9 — vendor fix ↗
- ONTAP 9 — vendor fix ↗
- ONTAP 9 — vendor fix ↗
References
- https://curl.se/docs/CVE-2023-27535.html ↗
- https://curl.se/docs/CVE-2023-27536.html ↗
- https://curl.se/docs/CVE-2023-27537.html ↗
- https://curl.se/docs/CVE-2023-27538.html ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2023