FAS and V-Series Storage Systems Discussions

Vulnerabilities

OpenSSH 7.4 Not Installed Multiple Vulnerabilities

Device is a FAS2240-2

Version 8.2.5 7

Is this system vulnerable. Many Linux systems run an older version of OpenSSH but they are patch to version 7.4.

This is information is easy to find for many operating systems and appliacnes but NetApp seems to lack in simple listings of vulnerability documentation and mitigations.

Does NetApp do this.

I found this link "https://security.netapp.com/advisory/ntap-20171130-0002/" but it states nothing for mitigation. Like what version is fixed.

Being that NetApp should be PCI compliant which means it must be patched for all Critical and High vulnerabilites I would hope it is or can be patched.

Teh CVE's in question are  CVE-2016-10012, CVE-2016-10011, CVE-2016-10010, CVE-2016-10009

3 REPLIES 3
Highlighted

Re: Vulnerabilities

I know it's not obvious when looking at the specific page, but this text to the right of "Overview" are additional tabs of information.

Affected Products     Remediation    Revision History

 

If you click on Remediation, you will see ONTAP 8.2.5 7-Mode has a fix.

Re: Vulnerabilities

Andris, we have been looking a for a while regarding this same CVE. The notes all state that this has been fixed in newer releases on OnTap, but additional scans to the Netapp devices still show they are running OpenSSH 7.2. Was this fixed via a backport? If not, how was it fixed. If it is fixed with a backport, is there any official documentation stating this?

Re: Vulnerabilities

Hello,

 

It is not uncommon for third party to be patched rather than upgraded in ONTAP. Therefore scan results identified using detected third party software versions can often be incorrect. I am unaware of any ONTAP documentation that covers updating third party code versus patching it. As each security advisory states, they "should be considered the single source of current, up-to-date, authorized and accurate information from NetApp.". Advisory ntap-20171130-0002 covers CVE-2016-10012, CVE-2016-10011, CVE-2016-10010, and CVE-2016-10009 and it reflects that ONTAP 8.2.5 is the first fixed-in release for these CVEs.

Forums