{"status":"success","advisory":{"_id":"683547225b16347a91c39ceb","kb_acknowledgements":null,"kb_affected_list":[],"kb_bad_data":false,"kb_cve":["CVE-2016-8858"],"kb_exploitation":"Public","kb_fixes":[],"kb_impact":"None - no longer considered a vulnerability.","kb_internal_notes":[{"burt":"1067426","jira":"","product":"Cluster Network Switch (NetApp CN1610)"},{"burt":"1067424","jira":"","product":"Clustered Data ONTAP"},{"burt":"1067429","jira":"","product":"Data ONTAP operating in 7-Mode"},{"burt":"1067430","jira":"","product":"Management Network Switch (NetApp CN1601)"},{"burt":"1155317","jira":"","product":"NetApp Cloud Backup (formerly AltaVault)"},{"burt":"","jira":"SECURITY-273","product":"NetApp SolidFire & HCI Storage Node (Element Software)"},{"burt":"1155316","jira":"","product":"NetApp SteelStore Cloud Integrated Storage"},{"burt":"1067431","jira":"","product":"NetApp VASA Provider for Clustered Data ONTAP 9.6 and above"},{"burt":"1067428","jira":"","product":"ONTAP Select Deploy administration utility"},{"burt":"1067432","jira":"","product":"OnCommand Balance"},{"burt":"1067433","jira":"","product":"OnCommand Performance Manager (Unified Manager Performance Pkg)"},{"burt":"1155318","jira":"","product":"OnCommand Unified Manager Core Package"},{"burt":"1067434","jira":"","product":"OnCommand Unified Manager for Clustered Data ONTAP"},{"burt":"1067436","jira":"","product":"Service Processor"},{"burt":"1067438","jira":"","product":"StorageGRID (formerly StorageGRID Webscale)"},{"burt":"1067437","jira":"","product":"StorageGRID9 (9.x and prior)"}],"kb_investigating_list":[],"kb_num":"9010000","kb_ref":[],"kb_rev_history":[{"comment":"Initial Public Release","date":"20180201","version":"1.0"},{"comment":"Changed CVSS score to 0.0 - this is no longer considered a vulnerability, Final status","date":"20210415","version":"2.0"}],"kb_revised_list":[],"kb_scoring":{"CVE-2016-8858":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"},"kb_scoring_calc":[{"cve_id":"CVE-2016-8858","range":"NONE","score":0.0,"vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"}],"kb_status":"Final","kb_summary":"Multiple NetApp products incorporate the OpenSSH software libraries. \r\n\r\n\r\n** DISPUTED ** The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that \"OpenSSH upstream does not consider this as a security issue.\"","kb_title":"CVE-2016-8858 OpenSSH Vulnerability in NetApp Products","kb_unaffected_list":["7-Mode Transition Tool","ATTO FibreBridge - 6500N","Brocade Fabric Operating System Firmware","Cloud Manager","Cluster Network Switch (NetApp CN1610)","Clustered Data ONTAP","Clustered Data ONTAP Antivirus Connector","Data ONTAP operating in 7-Mode","E-Series SANtricity Storage Manager","E-Series SANtricity Web Services (REST API) for Web Services Proxy","FAS/AFF BIOS","Host Utilities - SAN for Linux","Host Utilities - SAN for Windows","Management Network Switch (NetApp CN1601)","MetroCluster Tiebreaker for clustered Data ONTAP","NetApp Cloud Backup (formerly AltaVault)","NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)","NetApp Manageability SDK","NetApp NFS Plug-in for VMware VAAI","NetApp SANtricity SMI-S Provider","NetApp SMI-S Provider","NetApp SolidFire & HCI Storage Node (Element Software)","NetApp SteelStore Cloud Integrated Storage","NetApp Storage Encryption","NetApp VASA Provider for Clustered Data ONTAP 9.6 and above","ONTAP Select Deploy administration utility","OnCommand API Services","OnCommand Balance","OnCommand Insight","OnCommand Performance Manager (Unified Manager Performance Pkg)","OnCommand Unified Manager Core Package","OnCommand Unified Manager for Clustered Data ONTAP","OnCommand Workflow Automation","Open Systems SnapVault Agent","Service Processor","Single Mailbox Recovery","Snap Creator Framework","SnapCenter","SnapDrive for Unix","SnapDrive for Windows","SnapManager for Exchange","SnapManager for Hyper-V","SnapManager for MS SQL","SnapManager for Oracle","SnapManager for SAP","SnapManager for Sharepoint","Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.6 and above","Storage Services Connector","StorageGRID (formerly StorageGRID Webscale)","StorageGRID9 (9.x and prior)","System Manager 9.x","Virtual Storage Console for VMware vSphere 9.6 and above"],"kb_workarounds":"None at this time.","ntap_advisory_id":"NTAP-20180201-0001","adv_id":"ntap-20180201-0001","published_date":"2018-02-01T00:00:00","updated_date":"2021-04-15T00:00:00","inserted_date":"2025-05-27T05:01:22.312000","modified_date":null}}