Information Disclosure Vulnerability in ONTAP 9
CVE-2023-27317

4.3MEDIUM

Key Information:

Vendor
Netapp
Status
Vendor
CVE Published:
15 December 2023

Summary

ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked after a system reboot or power cycle or a single SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This could lead to disclosure of sensitive information to an attacker with physical access to the unlocked drives.

Affected Version(s)

ONTAP 9 9.12.1P8

ONTAP 9 9.13.1P4

ONTAP 9 9.13.1P5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-27317 : Information Disclosure Vulnerability in ONTAP 9 | SecurityVulnerability.io