CVE-2023-48795 SSH Terrapin Attack vulnerability reported for SolidFire and HCI Nodes
Applies to
- NetApp HCI & SolidFire Storage nodes
- NetApp HCI & SolidFire Management node (mNode)
- Element Software
- SSH
Issue
Security scanner reports the SSH Terrapin attack for the NetApp HCI & SolidFire Storage nodes and Management node
SSH Terrapin Prefix Truncation Weakness (CVE-2023-48795)The remote SSH server is vulnerable to a man-in-the-middle prefix truncation weakness known as Terrapin. This can allow a remote, man-in-the-middle attacker to bypass integrity checks and downgrade the connection's security.