Does CVE-2022-38023 have impact to Domain-Tunnel Authentication
Applies to
- ONTAP 9
- Domain Tunnel
- RPC_NETLOGON
Issue
- ONTAP configured with domain-tunnel for domain-based authentication
::> security login domain-tunnel show
Note: If nothing is return by this command, then a domain-tunnel does not exist for the cluster
- Access is denied when using domain users for SSH, API, or GUI login, such as System Manager
-
SECD logs show the following:
FAILURE: Pass-through authentication failed. (Status: 0xC000005E)