Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (HTTP service): An unauthenticated attacker performs administrative
Impact
An unauthenticated attacker performs administrative actions on the utility that deploys and manages ONTAP Select clusters. That is control over the storage serving the GPU fleet, with no credential at all.
Who can reach it
Any network path to the Deploy appliance's HTTP service. The service binds to the network and does not require authentication, so a foothold on the management VLAN is enough.
What to do
Upgrade ONTAP Select Deploy 2.12/2.12.1 to a fixed release. Until then, firewall the Deploy appliance so only the storage admin jump host can reach it, and check the Deploy audit trail for actions you did not initiate.
References
Related entries
- NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, soCVE-2019-5505 · NetApp ONTAP Select Deploy administration utility (credential transport)Critical
- NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code andCVE-2019-5509 · NetApp ONTAP Select Deploy administration utility (code injection)Critical
- Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCVE-2019-6438 · Slurm (32-bit RPC handling)Critical
- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCVE-2019-7276 · Optergy Proton / Enterprise building management platformCritical
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCVE-2019-9569 · Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra serviceCritical
- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCVE-2020-12812 · Fortinet FortiOS SSL-VPNCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.