What are you looking for ?
Infinidat
Articles_top

Security Advisory: Patches for December 2022 Heimdal Resolved Vulnerabilities in NetApp Products

Heimdal versions prior to 7.7.1 susceptible to vulnerabilities

NetApp, Inc. had published a security advisory concerning resolved vulnerabilities.

This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.

Advisory ID: NTAP-20230216-0008
Version: 7.0
Last updated: 01/24/2024
Status: Final.
CVEs: CVE-2022-42898, CVE-2022-3437, CVE-2022-41916, CVE-2021-44758, CVE-2021-3671, CVE-2022-44640, CVE-2019-14870

Overview

Summary
Multiple NetApp products incorporate Heimdal. Heimdal versions prior to 7.7.1 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

Ontap select deploy administration utility:
Affected by only CVE-2022-42898.

Vulnerability scoring details:

CVE

Score

Vector

CVE-2019-14870

5.4 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVE-2021-3671

6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-44758

7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-3437

6.5 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2022-41916

7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-42898

8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44640

9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploitation and public announcements
NetApp is aware of public discussion of this vulnerability.

References

Affected products

  • Management Services for Element Software and NetApp HCI
  • NetApp E-Series Performance Analyzer
  • Ontap Select Deploy administration utility

Remediation:

Software versions and fixes
NetApp’s currently available patches are listed below.

Product

First Fixed in Release

Management Services for Element Software and NetApp HCI

https://mysupport.netapp.com/site/products/all/details/mgmtservices/downloads-tab/download/63086/2.23.64

NetApp E-Series Performance Analyzer

NetApp E-Series Performance Analyzer has no plans to address this vulnerability. See the EOA announcement for more information.

Ontap Select Deploy administration utility

https://mysupport.netapp.com/site/products/all/details/ontapselect-deploy/downloads-tab/download/62910/9.13.1

Workarounds: None at this time.

Obtaining software fixes
Software fixes will be made available through the NetApp Support website in the Software Download section.

https://mysupport.netapp.com/site/downloads/

Customers who do not have access to the Support website should contact Technical Support at the number below to obtain the patches.

Contact information
Check http://mysupport.netapp.com for further updates.
For questions, contact NetApp at:

Technical support
mysupport.netapp.com
1 888 4 NETAPP (1 888 463 8277) (U.S. and Canada)
+00 800 44 638277 (EMEA/Europe)
+800 800 80 800 (AsiaPac)

Revision history:

Status of this notice: Final.

This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.

This advisory is posted at the following link:
https://security.netapp.com/advisory/NTAP-20230216-0008

Revision History

Revision #

Date

Comments

1.0

20230216

Initial public release

2.0

20230228

Ontap 9 (formerly Clustered Data Ontap) moved to Products Not Affected

3.0

20230307

NetApp E-Series Performance Analyzer moved to Won’t Fix status

4.0

20230328

Management Services for Element Software and NetApp HCI added to Software Versions and Fixes

5.0

20230501

NetApp SolidFire & HCI Management Node moved to Affected Products

6.0

20231004

NetApp SolidFire & HCI Management Node moved to Products Not Affected

7.0

20240124

Ontap Select Deploy administration utility 9.13.1 added to Software Versions and Fixes, Final status

This document is provided solely for informational purposes. All information is based upon NetApp’s current knowledge and understanding of the hardware and software products tested by NetApp, and the methodology and assumptions used by NetApp. The company is not responsible for any errors or omissions that may be contained herein, and no warranty, representation, or other legal commitment or obligation is being provided by NetApp. © 2022 NetApp, Inc. All rights reserved.

Articles_bottom
AIC
ATTO
OPEN-E