Home / Security / Advisories / NTAP-20230803-0011
NTAP-20230803-0011 — CVE-2023-3446 OpenSSL Vulnerability in NetApp Products
Published 2023-08-03 · Updated 2026-02-13 · Status: Interim · Exploitation: Public · Severity: MEDIUM 5.3 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · Brocade SAN firmware · E-Series / SANtricity · Baseboard management controllers · Other NetApp products · SolidFire / NetApp HCI · Cloud Backup / AltaVault / SteelStore · ONTAP · OnCommand family · SnapManager / Snap utilities | ONTAP-relevant | highest CVSS: 5.3
CVEs in this advisory
- CVE-2023-3446 — MEDIUM · CVSS 5.3 · site index
What the CVE records say
CVE-2023-3446 — Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Denial of Service attack. The function DH_check() is itself called by a number of other OpenSSL functions. An application calling any of those other functions may similarly be affected. The other functions affected by this are DH_check_ex() and EVP_PKEY_param_check(). Also vulnerable are the OpenSSL dhparam and pkeyparam command line applications when using the '-check' option. The OpenSSL SSL/TLS implementation is not affected by this issue. The OpenSSL 3.0 and 3.1 FIPS providers are not affected by this issue.
Impact
Successful exploitation of this vulnerability could lead to Denial of Service (DoS).
Affected products
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for VMware vSphere
- Brocade Fabric Operating System Firmware
- E-Series SANtricity OS Controller Software 11.x
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250
- FAS/AFF Baseboard Management Controller (BMC) - A320
- FAS/AFF Baseboard Management Controller (BMC) - A800/C800
- FAS/AFF Baseboard Management Controller (BMC) - A900/9500
- FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750
- FAS/AFF Baseboard Management Controller (BMC) - FAS2820
- FAS/AFF Service Processor - A300/8200
- FAS/AFF Service Processor - A700/9000
Official fixes
- Active IQ Unified Manager for VMware vSphere — vendor fix ↗
- E-Series SANtricity OS Controller Software 11.x — vendor fix ↗
- FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250 — vendor fix ↗
- FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750 — vendor fix ↗
- FAS/AFF Baseboard Management Controller (BMC) - A900/9500 — vendor fix ↗
- FAS/AFF Baseboard Management Controller (BMC) - FAS2820 — vendor fix ↗
- FAS/AFF Service Processor - A300/8200 — vendor fix ↗
- FAS/AFF Service Processor - A700/9000 — vendor fix ↗
- Management Services for Element Software and NetApp HCI — vendor fix ↗
- NetApp Manageability SDK — vendor fix ↗
- OnCommand Workflow Automation — vendor fix ↗
- ONTAP Select Deploy administration utility — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2023