CVE-2023-27314: Denial of Service Vulnerability in ONTAP 9
Published Oct 12, 2023
·Updated
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to cause a crash of the HTTP service.
Affected Software
9 affected components
NetApp Clustered Data ONTAP>=9.0<9.8
NetApp Clustered Data ONTAP=9.8
NetApp Clustered Data ONTAP=9.8-p7
NetApp Clustered Data ONTAP=9.9.1
NetApp Clustered Data ONTAP=9.9.1-p3
NetApp Clustered Data ONTAP=9.10.0
NetApp Clustered Data ONTAP=9.10.1
NetApp Clustered Data ONTAP=9.12.0
NetApp Clustered Data ONTAP=9.13.0
Event History
Oct 12, 2023
CVE Published
via MITRE·06:26 PM
Data Sourced
via MITRE·06:26 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-27314.
2
Which versions of ONTAP are affected?
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2, and 9.13.1 are affected.
3
What is the severity of CVE-2023-27314?
The severity of CVE-2023-27314 is high, with a CVSS score of 7.5.
4
What is the impact of this vulnerability?
This vulnerability could allow a remote unauthenticated attacker to cause a crash of the HTTP service.
5
Where can I find more information about CVE-2023-27314?
You can find more information about CVE-2023-27314 at the following link: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20231009-0001/)