ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a
vulnerability which will cause all SAS-attached FIPS 140-2 drives to
become unlocked after a system reboot or power cycle or a single
SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This
could lead to disclosure of sensitive information to an attacker with
physical access to the unlocked drives.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 07 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 22 Nov 2024 12:00:00 +0000

Type Values Removed Values Added
References

cve-icon MITRE

Status: PUBLISHED

Assigner: netapp

Published:

Updated: 2025-05-07T20:42:38.376Z

Reserved: 2023-02-28T17:20:57.462Z

Link: CVE-2023-27317

cve-icon Vulnrichment

Updated: 2024-08-02T12:09:43.287Z

cve-icon NVD

Status : Modified

Published: 2023-12-15T23:15:07.140

Modified: 2024-11-21T07:52:38.333

Link: CVE-2023-27317

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.