Network Appliance iSCSI Authentication Bypass Vulnerability
BID:15197
Info
Network Appliance iSCSI Authentication Bypass Vulnerability
| Bugtraq ID: | 15197 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2005 12:00AM |
| Updated: | Oct 25 2005 12:00AM |
| Credit: | Thomas H. Ptacek, Matasano Security discovered this vulnerability. |
| Vulnerable: |
NetApp Data ONTAP 7.0 NetApp Data ONTAP 6.5 NetApp Data ONTAP 6.4 |
| Not Vulnerable: |
NetApp Data ONTAP 7.0.2 |
Discussion
Network Appliance iSCSI Authentication Bypass Vulnerability
Network Appliance's iSCSI implementation is susceptible to an authentication bypass vulnerability.
This issue allows attackers to bypass iSCSI authentication, allowing them to read/write arbitrary data contained in iSCSI volumes. Access to potentially sensitive information will aid them in further attacks. Data destruction and alteration is also possible.
Unmapped LUNs, and LUNs mapped for use by only Fibre Channel initiators are not vulnerable to this issue.
Versions 6.4, 6.5, and 7.0 are reported vulnerable to this issue; other versions may also be affected.
Network Appliance's iSCSI implementation is susceptible to an authentication bypass vulnerability.
This issue allows attackers to bypass iSCSI authentication, allowing them to read/write arbitrary data contained in iSCSI volumes. Access to potentially sensitive information will aid them in further attacks. Data destruction and alteration is also possible.
Unmapped LUNs, and LUNs mapped for use by only Fibre Channel initiators are not vulnerable to this issue.
Versions 6.4, 6.5, and 7.0 are reported vulnerable to this issue; other versions may also be affected.
Exploit / POC
Network Appliance iSCSI Authentication Bypass Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Network Appliance iSCSI Authentication Bypass Vulnerability
Solution:
The reporter of this issue states that Network Appliance has released version 7.0.2 of Data ONTAP to address this issue. An advisory from Network Appliance is stated to be available at:
http://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&Display=169359
Appropriate access to now.netapp.com is required to access this document.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
The reporter of this issue states that Network Appliance has released version 7.0.2 of Data ONTAP to address this issue. An advisory from Network Appliance is stated to be available at:
http://now.netapp.com/NOW/cgi-bin/bol?Type=Detail&Display=169359
Appropriate access to now.netapp.com is required to access this document.
--
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Network Appliance iSCSI Authentication Bypass Vulnerability
References:
References:
- Network Appliance Support Services (Network Appliance)
- Network Appliance iSCSI Authentication Bypass ([email protected])