GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP 9 HTTP service: An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management and

CVE-2023-27314Control plane, storage & DevOpscurated

Impact

An unauthenticated attacker crashes the ONTAP HTTP service, taking down the management and REST interfaces. Automation that provisions volumes or rotates snapshots for the GPU fleet stops working, and so does the operator's ability to respond.

Who can reach it

Network reach to the HTTP service on an ONTAP 9 system below 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 or 9.13.1. No account needed.

What to do

Upgrade to the fixed ONTAP patch level. Meanwhile restrict the management LIF to an admin network - the data path stays up when the HTTP service dies, but you lose control of it.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.