CVE-2023-27317
Information Disclosure Vulnerability in ONTAP 9
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a
vulnerability which will cause all SAS-attached FIPS 140-2 drives to
become unlocked after a system reboot or power cycle or a single
SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This
could lead to disclosure of sensitive information to an attacker with
physical access to the unlocked drives.
ONTAP 9 versiones 9.12.1P8, 9.13.1P4 y 9.13.1P5 son susceptibles a una vulnerabilidad que hará que todas las unidades FIPS 140-2 conectadas a SAS se desbloqueen después de reiniciar el sistema o reiniciar el sistema o un único FIPS 140 conectado a SAS. -2 unidad para desbloquearse después de la reinserción. Esto podría dar lugar a la divulgación de información confidencial a un atacante con acceso físico a las unidades desbloqueadas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-28 CVE Reserved
- 2023-12-15 CVE Published
- 2023-12-20 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.netapp.com/advisory/NTAP-20231215-0001 | 2023-12-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netapp Search vendor "Netapp" | Ontap Search vendor "Netapp" for product "Ontap" | 9.12.1 Search vendor "Netapp" for product "Ontap" and version "9.12.1" | p8 |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Search vendor "Netapp" for product "Ontap" | 9.13.1 Search vendor "Netapp" for product "Ontap" and version "9.13.1" | p4 |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Search vendor "Netapp" for product "Ontap" | 9.13.1 Search vendor "Netapp" for product "Ontap" and version "9.13.1" | p5 |
Affected
|