Skip to main content
NetApp Knowledge Base

ONTAP Tools for VMware vSphere: Vulnerabilities within ONTAP tools 9.x

Views:
90
Visibility:
Public
Votes:
0
Category:
virtual-storage-console-for-vmware-vsphere
Specialty:
virt
Last Updated:

Applies to

  • ONTAP tools for VMware vSphere (OTV) 9.13 P1
  • Vulnerable ciphers reported in OTV9.13 P1 for ports 8143, 8443 and 9083
  • HTTP OPTIONS vulnerability reported in OTV9.13 P1
  • OpenSSH vulnerability in ONTAP tools for VMware vSphere 9.13 P1
  • HSTS missing from HTTPS server on port 8443 in OTV 9.12

Issue

  • Vulnerable ciphers reported in OTV9.13 P1 for ports 8143, 8443 and 9083 : Vulnerable cipher suites TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA were detected on ports 8143(vscserver)8443(rpserver) and 9083(vp-server)  when ran  vulnerability scanner tool.
  • HTTP OPTIONS vulnerability reported in OTV9.13 P1: HTTP OPTIONS method is enabled for port: 8143. HTTP OPTIONS method although primarily used for debugging purpose can be exploited by an attacker to retrieve sensitive information regarding the system
  • OpenSSH vulnerability in ONTAP tools for VMware vSphere 9.13 P1 :  OpenSSH has released a Security Advisory and patches for CVE-2024-6387. Your product has been identified as using OpenSSH based on Blackduck data.
  • HSTS missing from HTTPS server on port 8443 in OTV 9.12 : vulnerability found via scanner tools such as Nessus 

 

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.