Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (HTTP service): An unauthenticated attacker performs administrative
Impact
An unauthenticated attacker performs administrative actions on the utility that deploys and manages ONTAP Select clusters. That is control over the storage serving the GPU fleet, with no credential at all.
Who can reach it
Any network path to the Deploy appliance's HTTP service. The service binds to the network and does not require authentication, so a foothold on the management VLAN is enough.
What to do
Upgrade ONTAP Select Deploy 2.12/2.12.1 to a fixed release. Until then, firewall the Deploy appliance so only the storage admin jump host can reach it, and check the Deploy audit trail for actions you did not initiate.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.