Database/Control plane, storage & DevOps

IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can send
Impact
An unauthenticated attacker who can send UDP to an ESS node knocks storage service over with malformed packets. This is the whole appliance that the GPU fleet reads training data from, so a single spoofable UDP flow stalls the cluster.
Who can reach it
Network reach to the ESS management or data interfaces. UDP, so it is spoofable and does not need a completed handshake or any account.
What to do
Upgrade ESS to 6.0.1.3 / 5.3.6.3 or later. In the meantime, filter the affected UDP ports at the fabric so only known cluster members can send to them.
References
Related entries
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
- Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05CVE-2021-45454 · Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 - power telemetry exposed through the Linux HWmon interfaceHigh
- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayCVE-2022-37122 · Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi)High
- FlyteAdmin (built-in OAuth authorization server, default client secret hashes): Turning on Flyte's built-inCVE-2022-39273 · FlyteAdmin (built-in OAuth authorization server, default client secret hashes)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.