Home / Security / Advisories / NTAP-20260617-0018
NTAP-20260617-0018 — CVE-2026-42770 OpenSSL Vulnerability in NetApp Products
Published 2026-06-17 · Updated 2026-10-07 · Status: Interim · Exploitation: Public · Severity: LOW 3.7 · ONTAP affected: Yes
Product family: Active IQ Unified Manager · Baseboard management controllers · SolidFire / NetApp HCI · NetApp Console / BlueXP · ONTAP · Other NetApp products · Brocade SAN firmware | ONTAP-relevant | highest CVSS: 3.7
CVEs in this advisory
- CVE-2026-42770 — LOW · CVSS 3.7 · site index
What the CVE records say
CVE-2026-42770 — Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup membership. Impact summary: A malicious peer which presents an X9.42 key carrying the victim's p and g parameters, a forged q = r (a small prime factor of the cofactor (p−1)/q_local), and a public value Y of order r can recover the victim's private key after a small number of key exchange attempts. When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the subgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's own q parameter, not the local key's q. The peer's domain parameters are then matched against the domain parameters of the private key, but the value of q is not compared. A malicious peer who presents an X9.42 key carrying the victim's p, g, a forged q = r (a small prime factor of the cofactor), and a public value Y of order r passes all checks. The shared secret then takes only r distinct values, leaking priv mod r. Repeating for each small-prime factor of the cofactor and combining via CRT recovers the full private key (Lim–Lee / small-subgroup-confinement attack). The realistic attack surface is narrow: principally CMP deployments with long-lived RA/CA DHX keys and bespoke enterprise or government applications using X9.42 DHX static keys with interactive protocols and therefore this issue was assigned Low severity. The FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this issue.
Impact
Successful exploitation of this vulnerability could lead to disclosure of sensitive information.
Affected products
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for VMware vSphere
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400
- Management Services for Element Software and NetApp HCI
- NetApp Console Agent Container (adc)
- NetApp Console Agent Container (cbs)
- NetApp Console Agent Container (cbs-backend)
- ONTAP Select Deploy administration utility
- AFF BIOS - A700s
- Active IQ Config Advisor
- Active IQ OneCollect
- Brocade Fabric Operating System Firmware
References
- https://openssl-library.org/news/secadv/20260609.txt ↗
- https://openssl-library.org/news/vulnerabilities/index.html#CVE-2026-42770 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2026