CVE-2016-1563: Input Validation
Published Apr 7, 2016
·Updated
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Affected Software
1 affected component
NetApp Clustered Data ONTAP=8.3.1
Event History
Apr 7, 2016
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1563?
CVE-2016-1563 has a high severity rating due to its potential to allow man-in-the-middle attacks.
2
How do I fix CVE-2016-1563?
To mitigate CVE-2016-1563, upgrade to a patched version of NetApp Clustered Data ONTAP that properly verifies X.509 certificates.
3
What does CVE-2016-1563 affect?
CVE-2016-1563 affects NetApp Clustered Data ONTAP version 8.3.1.
4
What is the main risk associated with CVE-2016-1563?
The main risk of CVE-2016-1563 is that it allows attackers to spoof TLS servers and potentially steal sensitive information.
5
Is CVE-2016-1563 common among NetApp software?
CVE-2016-1563 is a known vulnerability specifically affecting the 8.3.1 version of NetApp Clustered Data ONTAP.