CVE-2023-27317: Information Disclosure Vulnerability in ONTAP 9
ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked after a system reboot or power cycle or a single SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This could lead to disclosure of sensitive information to an attacker with physical access to the unlocked drives.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27317?
CVE-2023-27317 is considered a medium severity vulnerability due to the potential unauthorized access to FIPS 140-2 drives.
How do I fix CVE-2023-27317?
To fix CVE-2023-27317, users should upgrade to the patched versions of NetApp ONTAP, specifically versions 9.12.1P9, 9.13.1P6, or later.
What systems are affected by CVE-2023-27317?
CVE-2023-27317 affects NetApp ONTAP versions 9.12.1P8, 9.13.1P4, and 9.13.1P5.
What impact does CVE-2023-27317 have on data security?
The impact of CVE-2023-27317 can lead to FIPS 140-2 drives being unlocked improperly, potentially allowing unauthorized access to sensitive data.
Is there a workaround for CVE-2023-27317?
No reliable workaround for CVE-2023-27317 has been provided; upgrading to the latest version is recommended.