#1 Trending Cybersecurity News & Magazine
Thursday, September 28, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Blacktech APT

    BlackTech APT Group Exploits Router Weaknesses to Penetrate Corporate Networks

    Wolphv ransomware group

    New Wolphv Ransomware Group on the Dark Web Found Trying to Make a Name

    SiegedSec Hacker Group

    SiegedSec Hacker Group Announces Cyber Attack on Pemalang region of Indonesia

    Kokoro Cyber Attack

    Kokoro Cyber Attack Exposes Donor Data of Over 40 UK Charitable Organizations

    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    Blacktech APT

    BlackTech APT Group Exploits Router Weaknesses to Penetrate Corporate Networks

    Wolphv ransomware group

    New Wolphv Ransomware Group on the Dark Web Found Trying to Make a Name

    SiegedSec Hacker Group

    SiegedSec Hacker Group Announces Cyber Attack on Pemalang region of Indonesia

    Kokoro Cyber Attack

    Kokoro Cyber Attack Exposes Donor Data of Over 40 UK Charitable Organizations

    ZenLedger data sale

    ZenLedger Data Leak Claim Surfaces on the Dark Web

    CACTUS Cyber Attack

    Unraveling the CACTUS Ransomware Group’s Recent Exploits

    MOVEit Breach Statistics

    Zero-Day Exploitation Impact: MOVEit Breach Statistics Reach 2,120 Organization

    MEDUSA Cyber Attack

    MEDUSA Ransomware Group Strikes Again: Italian Company and Canadian Firm Latest Victims

    Ferguson Wellman cyber attack

    50 Targets and Counting: LostTrust Claims Ferguson Wellman Cyber Attack

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    threat landscape

    The Three Trends to Watch in the Growing Threat Landscape

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Mandatory Dark Web Monitoring for Indian Companies: SEBI Bolsters Cybersecurity Measures

    Tesla Data Leak

    Massive Tesla Data Leak Exposing Over 75000 Staff Attributed to Former Employees

    Cybersecurity Primer

    Bridging the Gap: Cybersecurity Primer to Address Woes Surrounding US Government Officials

    Executive order for cybersecurity

    White House Directs Federal Agencies to Enhance Cybersecurity Amid Exposure Concerns

    AI Cyber Challenge

    Biden-Harris Administration Introduces AI Cyber Challenge, Offering $20 Million Reward

    aws agent hijack

    New Research Exposes Advanced Cyber Threat – Attackers Hijack AWS Agent to Control Endpoints

    HUB cyber security

    Investors Sue HUB Cyber Security for Misleading Statements on Mount Rainier Merger

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Bureau Raises $16.5M in Series A Funding

    Bureau Raises $16.5M in Series A Funding to Drive Global Expansion and Combat Cyber Fraud

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

CERT-In Issues Alert on Five NetApp Vulnerabilities; Risks Include DoS Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued an alert on a series of NetApp vulnerabilities

Ashish Khaitan by Ashish Khaitan
June 5, 2023 - Updated on June 6, 2023
in Firewall Daily, Vulnerabilities
0
NetApp vulnerabilities
664
SHARES
3.7k
VIEWS
Share on LinkedInShare on Twitter

The Indian Computer Emergency Response Team (CERT-In) has issued an alert on a series of NetApp vulnerabilities, potentially exposing NetApp products to risks such as denial of service (DoS) attacks, sensitive information disclosure, and data manipulation.

In response to a query by The Cyber Express, NetApp said that they have a robust product security vulnerability and response handling policy. “We follow secure development principles throughout our product development lifecycle and improve on our secure-development programs on a continuing basis,” the official response read.

You might also like

Johnson Controls Data Breach Puts the Firm At Immediate Risk

Unitex Cyber Attack Poses the Same Question of Third-Party Vendor Cybersecurity

BlackTech APT Group Exploits Router Weaknesses to Penetrate Corporate Networks

Moreover, they stated that NetApp tracks published vulnerabilities and maintain a program whereby customers and researchers submit information about potential vulnerabilities.

Below are the security advisories issued on the company’s website:

  • HCI affected: https://security.netapp.com/advisory/ntap-20230601-0001/
  • AIQ UM only product listed as affected: https://security.netapp.com/advisory/ntap-20230601-0004/
  • No products listed as affected: https://security.netapp.com/advisory/ntap-20230601-0008/
  • HCI affected: https://security.netapp.com/advisory/ntap-20230601-0009/
  • HCI affected: https://security.netapp.com/advisory/ntap-20230601-0010/

Unveiling the NetApp vulnerabilities

Multiple NetApp products, spanning a range of system technologies, were found to harbor vulnerabilities.

Here are the systems and technologies affected by the NetApp vulnerabilities

Active IQ Unified Manager for Linux
Active IQ Unified Manager for Microsoft Windows
Active IQ Unified Manager for VMware vSphere
Astra Trident
E-Series SANtricity OS Controller Software 11.x
E-Series SANtricity Unified Manager and Web Services Proxy
NetApp BlueXP
NetApp HCI Baseboard Management Controllers (BMC) such as H300S/H500S/H700S/H410S and H410C.

These are the specific NetApp vulnerabilities that were found in these products. 

NetApp vulnerabilities: The latest five

CVE-2023-1829: Linux Kernel vulnerability in NetApp products

NetApp products integrating the Linux kernel, specifically versions before 6.3, are susceptible to this vulnerability. Exploiting it can result in the unauthorized disclosure of sensitive information, tampering with data, or triggering a DoS attack.

CVE-2023-1989: Linux Kernel vulnerability in NetApp products

Similar to the previous vulnerability, this affects NetApp products incorporating the Linux kernel. Versions prior to 6.3-rc4 are at risk, potentially leading to the disclosure of sensitive information, data manipulation, or a DoS attack.

CVE-2023-30846: Node.js vulnerability in NetApp products

This vulnerability pertains to NetApp products utilizing Node.js, specifically impacting versions prior to 1.8.0 of the Node.js library typed-rest-client. Successful exploitation of this vulnerability can expose sensitive information.

CVE-2023-20873: Spring Boot vulnerability in NetApp products

Multiple NetApp products that incorporate Spring Boot are affected by this vulnerability. It encompasses versions 3.0.0 through 3.0.5, 2.7.0 through 2.7.10, and older unsupported versions. This vulnerability could lead to disclosing sensitive information, unauthorized data modifications, or a DoS attack if exploited.

CVE-2023-2236: Linux Kernel vulnerability in NetApp products

NetApp products that integrate the Linux kernel, particularly versions 5.19 before 6.1-rc7, are vulnerable to this specific vulnerability. Successful exploitation could result in the unauthorized disclosure of sensitive information, data manipulation, or a DoS attack.

NetApp recently introduced significant changes across various product domains, including the release of their latest entry-level ASA (All-SAN Array) block storage devices, namely the ASA A150 and A250.

Additionally, it also announced improvements to its Advance subscription model, which now comes with a ransomware data guarantee and data availability assurances that boast an impressive uptime of six nines, equivalent to slightly over 30 seconds of downtime per year.

Mitigation and best practices for fixing vulnerability in NetApp products

Immediate action is crucial to mitigate vulnerabilities and fortify the security of NetApp product deployments. NetApp product users should consider the following steps, as shared by the NetApp advisories. 

  • Patch and update: Regularly update NetApp products and associated software with NetApp’s latest patches and security updates. This ensures that known vulnerabilities are addressed promptly.
  • Implement robust security measures: Employ robust security measures, such as firewalls, intrusion detection systems, and endpoint protection, to fortify network defenses and detect potential threats.
  • Enforce access controls: Utilize strong access controls, including unique user accounts, strong passwords, and the principle of least privilege, to limit unauthorized access to sensitive information and system functionalities.
  • Regular data backups: Maintain regular backups of critical data to minimize the impact of potential data manipulation or loss resulting from an attack. Implement appropriate backup strategies and ensure their integrity.
  • Stay Informed: Stay abreast of security advisories and updates provided by NetApp and other trusted sources. Regularly monitor emerging threats and vulnerabilities to address any new risks proactively.

By following these recommendations, NetApp product users can significantly enhance the security of their deployments and effectively address vulnerabilities.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Previous Post

Microsoft Edge Vulnerability Report Addresses a Low Severity Bug

Next Post

Nova Scotia Cyber Attack Attributed to MOVEit Transfer Vulnerability Exploitation

Ashish Khaitan

Ashish Khaitan

Ashish is a technical writer at The Cyber Express. He adores writing about the latest technologies and covering the latest cybersecurity events. In his free time, he likes to play horror and open-world video games.

Related Posts

Johnson Controls Data Breach
Data Breach News

Johnson Controls Data Breach Puts the Firm At Immediate Risk

by Ashish Khaitan
September 28, 2023
Unitex Cyber Attack
Firewall Daily

Unitex Cyber Attack Poses the Same Question of Third-Party Vendor Cybersecurity

by Vishwa Pandagle
September 28, 2023
Blacktech APT
Data Breach News

BlackTech APT Group Exploits Router Weaknesses to Penetrate Corporate Networks

by Ashish Khaitan
September 28, 2023
Wolphv ransomware group
Firewall Daily

New Wolphv Ransomware Group on the Dark Web Found Trying to Make a Name

by Vishwa Pandagle
September 28, 2023
SiegedSec Hacker Group
Firewall Daily

SiegedSec Hacker Group Announces Cyber Attack on Pemalang region of Indonesia

by Ashish Khaitan
September 28, 2023
Next Post
Nova Scotia cyber attack

Nova Scotia Cyber Attack Attributed to MOVEit Transfer Vulnerability Exploitation

Latest Issue is Out. Subscribe Now



Follow Us On Google News

Latest Cyber News

Blacktech APT
Data Breach News

BlackTech APT Group Exploits Router Weaknesses to Penetrate Corporate Networks

September 28, 2023
Wolphv ransomware group
Firewall Daily

New Wolphv Ransomware Group on the Dark Web Found Trying to Make a Name

September 28, 2023
SiegedSec Hacker Group
Firewall Daily

SiegedSec Hacker Group Announces Cyber Attack on Pemalang region of Indonesia

September 28, 2023
Kokoro Cyber Attack
Data Breach News

Kokoro Cyber Attack Exposes Donor Data of Over 40 UK Charitable Organizations

September 28, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin (Beta)

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance