NetAPP Alert
2723Warning Date
Severity Level
Warning Number
Target Sector
24 February, 2023
● High
2023-5475
All
NetApp has released security updates to address multiple vulnerabilities in the following products:
- Active IQ Unified Manager for VMware vSphere
- Management Services for Element Software and NetApp HCI
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
- NetApp HCI Baseboard Management Controller (BMC) - H410C
- ONTAP 9 (formerly Clustered Data ONTAP)
- ONTAP Select Deploy administration utility
Attacker could exploit these vulnerabilities to achieve the following:
- Sensitive Information Disclosure
- Denial of Service (DoS)
- addition or modification of data
The CERT team encourages users to update the affected versions and review NetApp security advisory:
- https://security.netapp.com/advisory/ntap-20230223-0002/
- https://security.netapp.com/advisory/ntap-20230223-0010/
- https://security.netapp.com/advisory/ntap-20230223-0005/
- https://security.netapp.com/advisory/ntap-20230223-0006/
- https://security.netapp.com/advisory/ntap-20230223-0001/
- https://security.netapp.com/advisory/ntap-20230223-0004/
- https://security.netapp.com/advisory/ntap-20230223-0003/
- https://security.netapp.com/advisory/ntap-20230223-0009