Security Advisory: Patches for December 2022 Heimdal Resolved Vulnerabilities in NetApp Products
Heimdal versions prior to 7.7.1 susceptible to vulnerabilities
This is a Press Release edited by StorageNewsletter.com on January 30, 2024 at 2:01 pmNetApp, Inc. had published a security advisory concerning resolved vulnerabilities.
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.
Advisory ID: NTAP-20230216-0008
Version: 7.0
Last updated: 01/24/2024
Status: Final.
CVEs: CVE-2022-42898, CVE-2022-3437, CVE-2022-41916, CVE-2021-44758, CVE-2021-3671, CVE-2022-44640, CVE-2019-14870
Overview
Summary
Multiple NetApp products incorporate Heimdal. Heimdal versions prior to 7.7.1 are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Impact
Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Ontap select deploy administration utility:
Affected by only CVE-2022-42898.
Vulnerability scoring details:
-
CVE
Score
Vector
5.4 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
6.5 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
6.5 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
7.5 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
8.8 (HIGH)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
9.8 (CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation and public announcements
NetApp is aware of public discussion of this vulnerability.
References
Affected products
- Management Services for Element Software and NetApp HCI
- NetApp E-Series Performance Analyzer
- Ontap Select Deploy administration utility
Remediation:
Software versions and fixes
NetApp’s currently available patches are listed below.
-
Product
First Fixed in Release
Management Services for Element Software and NetApp HCI
NetApp E-Series Performance Analyzer
NetApp E-Series Performance Analyzer has no plans to address this vulnerability. See the EOA announcement for more information.
Ontap Select Deploy administration utility
Workarounds: None at this time.
Obtaining software fixes
Software fixes will be made available through the NetApp Support website in the Software Download section.
https://mysupport.netapp.com/site/downloads/
Customers who do not have access to the Support website should contact Technical Support at the number below to obtain the patches.
Contact information
Check http://mysupport.netapp.com for further updates.
For questions, contact NetApp at:
Technical support
mysupport.netapp.com
1 888 4 NETAPP (1 888 463 8277) (U.S. and Canada)
+00 800 44 638277 (EMEA/Europe)
+800 800 80 800 (AsiaPac)
Revision history:
Status of this notice: Final.
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.
This advisory is posted at the following link:
https://security.netapp.com/advisory/NTAP-20230216-0008
Revision History
-
Revision #
Date
Comments
1.0
20230216
Initial public release
2.0
20230228
Ontap 9 (formerly Clustered Data Ontap) moved to Products Not Affected
3.0
20230307
NetApp E-Series Performance Analyzer moved to Won’t Fix status
4.0
20230328
Management Services for Element Software and NetApp HCI added to Software Versions and Fixes
5.0
20230501
NetApp SolidFire & HCI Management Node moved to Affected Products
6.0
20231004
NetApp SolidFire & HCI Management Node moved to Products Not Affected
7.0
20240124
Ontap Select Deploy administration utility 9.13.1 added to Software Versions and Fixes, Final status
This document is provided solely for informational purposes. All information is based upon NetApp’s current knowledge and understanding of the hardware and software products tested by NetApp, and the methodology and assumptions used by NetApp. The company is not responsible for any errors or omissions that may be contained herein, and no warranty, representation, or other legal commitment or obligation is being provided by NetApp. © 2022 NetApp, Inc. All rights reserved.