First published: Thu Apr 07 2016(Updated: )
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data ONTAP | =8.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1563 has a high severity rating due to its potential to allow man-in-the-middle attacks.
To mitigate CVE-2016-1563, upgrade to a patched version of NetApp Clustered Data ONTAP that properly verifies X.509 certificates.
CVE-2016-1563 affects NetApp Clustered Data ONTAP version 8.3.1.
The main risk of CVE-2016-1563 is that it allows attackers to spoof TLS servers and potentially steal sensitive information.
CVE-2016-1563 is a known vulnerability specifically affecting the 8.3.1 version of NetApp Clustered Data ONTAP.