Skip to main content
NetApp Knowledge Base

Vulnerability scanner reports 'OpenSSH version Not Installed Multiple Vulnerabilities' or to 'Upgrade to OpenSSH version'

Views:
1,673
Visibility:
Public
Votes:
2
Category:
ontap-9
Specialty:
core
Last Updated:

Applies to

  • ONTAP 9

Answer

Information

This is a common result from vulnerability scanners looking for versions. A product such as ONTAP might choose to not upgrade third-party code when a fix can be backported or configuration changed to address an issue. If there is a fixed version of a product listed in an advisory, then the fix was made regardless of the identified base OpenSSH version. Upgrading the product to avoid a scanner hit will result in maximum effort for short-term gain since OpenSSH will continue to have vulnerabilities discovered.

NetApp security advisories track the exploitability status of our products, not if the products ship vulnerable versions of software. Vulnerability scanners search for vulnerable versions of third-party code (among other things) but do not test for exploitability. The resulting report lists potential vulnerabilities for follow-up, showing that vulnerable versions of code may be in use but should not be considered a report of exploitable issues. Our posted security advisories are the authoritative answers for those issues and should be considered the single source of current, up-to-date, authorized and accurate information from NetApp for the CVE IDs they cover.

 

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.