Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP export policy enforcement (SMBv2/SMBv3): Export policy rules marked read-only are not
Impact
Export policy rules marked read-only are not actually enforced, so an authenticated SMB client writes to volumes the operator believed were read-only. Shared read-only dataset shares become writable, which means one tenant can poison training data everyone else consumes.
Who can reach it
An authenticated SMBv2 or SMBv3 client of a Clustered Data ONTAP 8.3 release-candidate system. The attacker needs no more than the read access they were legitimately granted.
What to do
Move off the affected 8.3 RC builds to a fixed ONTAP release. Afterwards, verify write behaviour empirically against each read-only export rather than trusting the policy display, and check the volumes for unexpected modifications.
References
Related entries
- Schneider Electric Data Center Expert 7.5.0 and earlier - zip upload: A crafted zip uploaded through the DCE UI canCVE-2018-7807 · Schneider Electric Data Center Expert 7.5.0 and earlier - zip uploadHigh
- CyberPower PowerPanel Business Edition 3.4.0 Agent/Center: Cross-site request forgery across all forms in the webCVE-2019-13071 · CyberPower PowerPanel Business Edition 3.4.0 Agent/CenterHigh
- Cisco Nexus 9000 ACI Mode (LLDP subsystem): A buffer overflow in the LLDP subsystem of Nexus 9000 switches in ACI modeCVE-2019-1901 · Cisco Nexus 9000 ACI Mode (LLDP subsystem)High
- IBM Spectrum Scale management GUI: Any authenticated GUI user - including a low-privilege monitoring account - runsCVE-2019-4715 · IBM Spectrum Scale management GUIHigh
- AMD ATI atillk64.sys - physical memory mapping driver: The AMD ATI atillk64.sys driver exposes routines that mapCVE-2020-12138 · AMD ATI atillk64.sys - physical memory mapping driverHigh
- Intel Data Center Manager Console: Improper input validation in the DCM Console lets an authenticated user escalateCVE-2020-12347 · Intel Data Center Manager ConsoleHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.