Unauthenticated Console Access via TCP Port 8023 on Cloud Volumes ONTAP
Applies to
- NetApp Cloud Volumes ONTAP (CVO) in Microsoft Azure
- ONTAP version 9.15.1P7, 9.16.1P7
Issue
A critical security vulnerability was identified during a penetration test. It is possible to connect to the management console over TCP port 8023 without authentication, including access to privileged (PRIV) mode.
Example log output / symptom:
Due to a penetration test on our NetApp CVO systems (Cluster MGT), it was possible to connect using TCP 8023 on the console without authentication, including privileged (PRIV) mode.
This security vulnerability is one of the highest classifications, with a CVSS score of 9.4!
ONTAPVERSION:9.15.1P7
- No error messages are logged; full privileged access is granted without authentication.
- Issue is reproducible on multiple clusters/nodes running affected ONTAP versions.
