ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a 
vulnerability which will cause all SAS-attached FIPS 140-2 drives to 
become unlocked after a system reboot or power cycle or a single 
SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This
 could lead to disclosure of sensitive information to an attacker with 
physical access to the unlocked drives. 
                
            References
                    | Link | Resource | 
|---|---|
| https://security.netapp.com/advisory/NTAP-20231215-0001/ | Vendor Advisory | 
| https://security.netapp.com/advisory/NTAP-20231215-0001/ | Vendor Advisory | 
| https://security.netapp.com/advisory/ntap-20231215-0001/ | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:52
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.3 | 
| References | 
 | |
| References | () https://security.netapp.com/advisory/NTAP-20231215-0001/ - Vendor Advisory | 
19 Dec 2023, 20:00
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://security.netapp.com/advisory/NTAP-20231215-0001/ - Vendor Advisory | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 4.6 | 
| CPE | cpe:2.3:a:netapp:ontap:9.12.1:p8:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9.13.1:p4:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9.13.1:p5:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo | |
| First Time | Netapp ontap Netapp | 
15 Dec 2023, 23:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-12-15 23:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27317
Mitre link : CVE-2023-27317
CVE.ORG link : CVE-2023-27317
JSON object : View
Products Affected
                netapp
- ontap
CWE
                