ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a
vulnerability which will cause all SAS-attached FIPS 140-2 drives to
become unlocked after a system reboot or power cycle or a single
SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This
could lead to disclosure of sensitive information to an attacker with
physical access to the unlocked drives.
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/NTAP-20231215-0001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Dec 2023, 20:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Netapp
Netapp ontap |
|
CWE | NVD-CWE-noinfo | |
References | () https://security.netapp.com/advisory/NTAP-20231215-0001/ - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
CPE | cpe:2.3:a:netapp:ontap:9.13.1:p5:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9.12.1:p8:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9.13.1:p4:*:*:*:*:*:* |
18 Dec 2023, 14:05
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-15 23:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-27317
Mitre link : CVE-2023-27317
CVE.ORG link : CVE-2023-27317
JSON object : View
Products Affected
netapp
- ontap
CWE