First published: Mon Jul 03 2017(Updated: )
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data ONTAP | =8.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-3997 is considered a critical severity vulnerability due to its potential for exploitation by man-in-the-middle attackers.
To fix CVE-2016-3997, ensure that SMB signing enforcement is enabled in the NetApp Clustered Data ONTAP configuration.
CVE-2016-3997 affects NetApp Clustered Data ONTAP version 8.3.1.
If exploited, CVE-2016-3997 could allow attackers to obtain sensitive information, gain unauthorized privileges, or cause a denial of service.
Yes, a possible workaround for CVE-2016-3997 is to manually enable SMB signing enforcement in the affected system's settings.