Database/Control plane, storage & DevOps
NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management and
Impact
An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management and REST interfaces. Automation that provisions volumes or rotates snapshots for the GPU fleet stops working, and so does the operator's ability to respond.
Who can reach it
Network reach to the HTTP service on an ONTAP 9 system below 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 or 9.13.1. No account needed.
What to do
Upgrade to the fixed ONTAP patch level. Meanwhile restrict the management LIF to an admin network - the data path stays up when the HTTP service dies, but you lose control of it.
References
Related entries
- Veeam Backup & Replication: Encrypted credentials in the configuration database can be obtainedCVE-2023-27532 · Veeam Backup & ReplicationHigh
- MinIO: Cluster returns all env vars incl. MINIO_SECRET_KEY and MINIO_ROOT_PASSWORDCVE-2023-28432 · MinIOHigh
- Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllers: An unauthenticated user can logCVE-2023-3127 · Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllersHigh
- AMD Radeon Graphics display driver - input validation: Improper input validation in the Radeon display driver letsCVE-2023-31320 · AMD Radeon Graphics display driver - input validationHigh
- ZKTeco BioTime v8.5.5 (iclock API path traversal): Unauthenticated arbitrary file read on the BioTime serverCVE-2023-38950 · ZKTeco BioTime v8.5.5 (iclock API path traversal)High
- KNX devices using KNX Connection Authorization Option 1 (BCU key): An attacker sets the BCU key on KNX devicesCVE-2023-4346 · KNX devices using KNX Connection Authorization Option 1 (BCU key)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.