CVE-2016-2183 TLS Protocol 64-bit Cipher Vulnerability in Multiple NetApp Products
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.
Subscribe to NTAP-20160915-0001 updates
Subscribe to NTAP-20160915-0001 advisory updates
Unsubscribe from NTAP-20160915-0001 advisory updates
Unsubscribe from NTAP-20160915-0001 advisory updates
Advisory ID: NTAP-20160915-0001 Version: 58.0 Last updated: 01/14/2022 Status: Final. CVEs: CVE-2016-2183
Summary
Multiple NetApp products utilize the TLS protocol. Any system using the TLS protocol with 64-bit block ciphers that are used in long running connections are vulnerable to a birthday attack referred to as SWEET32. When exploited, the vulnerability may lead to the unauthorized disclosure of information. This bulletin will be updated as additional information becomes available.
Impact
Exploitation of this vulnerability may lead to unauthorized disclosure of information.
Vulnerability Scoring Details
CVE | Score | Vector |
---|---|---|
CVE-2016-2183 | 3.7 (LOW) | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Exploitation and Public Announcements
NetApp is aware of public discussion of this vulnerability.
References
Affected Products
- 7-Mode Transition Tool
- AFF Baseboard Management Controller (BMC) - A700s
- Brocade Fabric Operating System Firmware
- Brocade Network Advisor Software
- Cloud Manager
- Clustered Data ONTAP
- Data ONTAP PowerShell Toolkit
- Data ONTAP operating in 7-Mode
- E-Series SANtricity Storage Manager
- NetApp Cloud Backup (formerly AltaVault)
- NetApp Host Agent
- NetApp Manageability SDK
- NetApp Plug-in for Symantec NetBackup
- NetApp SMI-S Provider
- NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software)
- NetApp VASA Provider for Clustered Data ONTAP 9.7 and above
- ONTAP Select Deploy administration utility
- OnCommand Insight
- OnCommand Shift
- OnCommand Unified Manager Core Package
- OnCommand Workflow Automation
- Open Systems SnapVault Agent
- Perfstat
- RBAC User Creator for Data ONTAP
- Service Processor
- Snap Creator Framework
- SnapCenter
- SnapCenter Plug-in for VMware vSphere
- SnapDrive for Unix
- SnapDrive for Windows
- SnapProtect
- Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above
- StorageGRID (formerly StorageGRID Webscale)
- StorageGRID9 (9.x and prior)
- System Setup
- Virtual Storage Console for VMware vSphere 6.x
- Virtual Storage Console for VMware vSphere 9.7 and above
Products Not Affected
- ATTO FibreBridge - 6500N
- Cluster Network Switch (NetApp CN1610)
- Clustered Data ONTAP Antivirus Connector
- E-Series SANtricity Management Plug-ins (VMware VASA (Windows))
- E-Series SANtricity Management Plug-ins (VMware vCenter (Linux))
- E-Series SANtricity Management Plug-ins (VMware vCenter)
- E-Series SANtricity Web Services (REST API) for Web Services Proxy
- FAS/AFF BIOS
- Host Utilities - SAN for Linux
- Host Utilities - SAN for Windows
- Management Network Switch (NetApp CN1601)
- MetroCluster Tiebreaker for clustered Data ONTAP
- NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in)
- NetApp NFS Plug-in for VMware VAAI
- NetApp SANtricity SMI-S Provider
- NetApp Storage Encryption
- OnCommand API Services
- OnCommand Balance
- OnCommand Performance Manager (Unified Manager Performance Pkg)
- OnCommand Plug-in for Microsoft
- OnCommand Unified Manager for Clustered Data ONTAP
- Single Mailbox Recovery
- SnapManager for Hyper-V
- SnapManager for Oracle
- SnapManager for SAP
- SnapManager for Sharepoint
- Storage Replication Adapter for Data ONTAP operating in 7-Mode 2.1
- Storage Services Connector
- System Manager 9.x
Software Versions and Fixes
NetApp's currently available patches are listed below.
Workarounds
- Clustered Data ONTAP: Beginning with version 9.0 ciphers can be manually disabled using the "security config" command:
::*> security config modify -supported-ciphers CURRENT_CIPHER_STRING:!3DES:!DES Note that "!DES" is only necessary if "!LOW" is not already present, which it is by default.
- Data ONTAP operating in 7-Mode: Beginning with version 8.2.5 the "high_security.enable" option will enable only the TLS v1.1 and v1.2 protocols which do not support the 3DES-CBC cipher.
- OnCommand Insight: https://kb.netapp.com/support/s/article/How-to-use-IBM-Cognos-configuration-application-edit-Supported-ciphersuites-setting-to-remove-3DES
- System Setup: Disable the 3DES and DES ciphers using https://support.microsoft.com/en-in/kb/245030.
- OnCommand Workflow Automation:
- Stop all of the WFA services.
- Make a backup copy and then edit this file: C:\Program Files\NetApp\WFA\jboss\standalone\configuration\standalone-full.xml
- Search for https-listner in the standalone-full.xml file.
- Remove all of the 3DES cipher suites in the 'enabled-cipher-suites' attribute.
- Save and close the standalone-full.xml file.
- Start the WFA services and make sure all the binaries have deployed successfully under the C:\Program Files\NetApp\WFA\jboss\standalone\deployments folder.
- Run manual acquisition from all the added data sources and ensure that all the acquisitions have finished without any issues.
Obtaining Software Fixes
Software fixes will be made available through the NetApp Support website in the Software Download section.
https://mysupport.netapp.com/site/downloads/
Customers who do not have access to the Support website should contact Technical Support at the number below to obtain the patches.
Contact Information
Check http://mysupport.netapp.com for further
updates.
For questions, contact NetApp at:
Technical Support
mysupport.netapp.com
1 888 4 NETAPP (1 888 463 8277) (U.S. and Canada)
+00 800 44 638277 (EMEA/Europe)
+800 800 80 800 (Asia/Pacific)
Status of This Notice
Final.
This advisory should be considered the single source of current, up-to-date, authorized and accurate information from NetApp regarding Full Support products and versions.
This advisory is posted at the following link:
https://security.netapp.com/advisory/NTAP-20160915-0001
Revision History
Revision # | Date | Comments |
---|---|---|
1.0 | 20160915 | Initial Public Release |
2.0 | 20160921 | SnapManager for Sharepoint moved to Products Not Affected |
3.0 | 20161006 | NetApp AltaVault moved to Affected Products |
4.0 | 20161108 | Config Advisor, Data ONTAP PowerShell Toolkit, RBAC User Creator for Data ONTAP removed due to being Toolchest products that are supported in the communities |
5.0 | 20161117 | SnapDrive for Windows added to Software Versions and Fixes, NetApp VASA Provider for Clustered Data ONTAP added to Affected Products |
6.0 | 20161122 | OnCommand Balance moved to Products Not Affected, SnapDrive for Unix moved to Affected Products and added to Software Versions and Fixes, NetApp Manageability SDK and Virtual Storage Console for VMware vSphere added to Software Versions and Fixes |
7.0 | 20161206 | OnCommand Workflow Automation moved to Affected Products |
8.0 | 20161213 | Fibre Channel Switch (Brocade) removed as covered product, Brocade Network Advisor Software moved to Affected Products, Brocade Network Operating System Firmware moved to Products Under Investigation |
9.0 | 20161220 | OnCommand Insight added to Workarounds. |
10.0 | 20170103 | OnCommand Insight Workaround modified to a KB link. |
11.0 | 20170117 | Clustered Data ONTAP added to Workarounds |
12.0 | 20170124 | Snap Creator Framework added to Software Versions and Fixes, Cluster Network Switch (NetApp CN1610) moved to Products Not Affected, SolidFire Element OS moved to Affected Products |
13.0 | 20170207 | OnCommand System Manager moved to Products Not Affected, OnCommand Cloud Manager, OnCommand Shift, and Open Systems SnapVault Agent moved to Affected Products, Perfstat moved to Affected Products and added to Software Versions and Fixes, System Setup added to Software Versions and Fixes and Workarounds |
14.0 | 20170214 | Management Network Switch (NetApp CN1601) moved to Products Not Affected, SnapCenter Plug-in for Microsoft SQL Server and SnapCenter Plug-in for Windows removed as they are now bundled with SnapCenter Server, ONTAP Select Deploy administration tool added to Software Versions and Fixes |
15.0 | 20170228 | SnapCenter Server moved to Affected Products, Open Systems SnapVault Agent added to Software Versions and Fixes |
16.0 | 20170315 | MetroCluster Tiebreaker for clustered Data ONTAP moved to Products Not Affected |
17.0 | 20170406 | OnCommand Workflow Automation added to Software Versions and Fixes |
18.0 | 20170407 | OnCommand Workflow Automation removed from Software Versions and Fixes |
19.0 | 20170508 | OnCommand Unified Manager Core Package (5.x) moved to Affected Products |
20.0 | 20170510 | NetApp AltaVault added to Software Versions and Fixes |
21.0 | 20170606 | StorageGRID and StorageGRID Webscale moved to Affected Products after further evaluation |
22.0 | 20170627 | 7-Mode Transition Tool moved to Affected Products, OnCommand Performance Manager (Unified Manager Performance Pkg) moved to Products not Affected |
23.0 | 20170711 | E-Series/EF-Series SANtricity Storage Manager added to Software Versions and Fixes |
24.0 | 20170718 | Workaround added for OnCommand Workflow Automation |
25.0 | 20170720 | 7-Mode Transition Tool moved to Won't Fix status. |
26.0 | 20170815 | Data ONTAP operating in 7-Mode added to Software Versions and Fixes |
27.0 | 20170907 | Workaround corrected for OnCommand Workflow Automation |
28.0 | 20170920 | FAS/V-Series Storage Replication Adapter for Clustered Data ONTAP moved to Affected Products and added to Software Versions and Fixes |
29.0 | 20171031 | StorageGRID Webscale added to Software Versions and Fixes |
30.0 | 20180118 | SnapCenter Server added to Software Versions and Fixes |
31.0 | 20180130 | Clustered Data ONTAP added to Software Versions and Fixes, Storage Replication Adapter for 7-Mode Data ONTAP moved to Products not Affected |
32.0 | 20180315 | OnCommand Shift moved to Won't Fix status |
33.0 | 20180411 | OnCommand Workflow Automation added to Software Versions and Fixes |
34.0 | 20180419 | Clarified NetApp Manageability SDK Software Versions and Fixes information, Clustered Data ONTAP Antivirus Connector moved to Affected Products |
35.0 | 20180423 | NetApp VASA Provider for Clustered Data ONTAP 7.0 and above added to Software Versions and Fixes |
36.0 | 20180522 | OnCommand API Services moved to Products Not Affected |
37.0 | 20180619 | Data ONTAP operating in 7-Mode and Virtual Storage Console for VMware vSphere 6.x REMOVED from Software Versions and Fixes |
38.0 | 20180621 | OnCommand Unified Manager for 7-Mode (core package) added to Software Versions and Fixes |
39.0 | 20180725 | Clustered Data ONTAP Antivirus Connector moved to Products not Affected |
40.0 | 20180825 | NetApp SMI-S Provider moved to Affected Products |
41.0 | 20181004 | NetApp Host Agent moved to Won't Fix status |
42.0 | 20181129 | Data ONTAP operating in 7-Mode added to Workarounds |
43.0 | 20181204 | Data ONTAP operating in 7-Mode added to Software Versions and Fixes |
44.0 | 20190128 | OnCommand Plug-in for Microsoft moved to Products Not Affected |
45.0 | 20190208 | Virtual Storage Console for VMware vSphere 6.x moved to Won't Fix status, Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above, NetApp VASA Provider for Clustered Data ONTAP 7.2 and above, Virtual Storage Console for VMware vSphere 7.2 and above fix links adjusted to 7.2.1 from 7.0 |
46.0 | 20190208 | NetApp VASA Provider for Clustered Data ONTAP 7.2 and above, Virtual Storage Console for VMware vSphere 7.2 and above, Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 7.2 and above added to Software Versions and Fixes |
47.0 | 20190531 | SnapProtect moved to Won't Fix status |
48.0 | 20190705 | Element Software (formerly SolidFire Element OS) moved to Affected Products |
49.0 | 20190726 | Brocade Network Operating System Firmware, Brocade Network Advisor Software and Brocade Fabric Operating System Firmware added to Software Versions and Fixes |
50.0 | 20190826 | NetApp SMI-S Provider added to Software Versions and Fixes |
51.0 | 20200324 | OnCommand Cloud Manager moved to Affected Products |
52.0 | 20200403 | SnapCenter Plug-in for VMware vSphere added to Software Versions and Fixes |
53.0 | 20200505 | OnCommand Workflow Automation moved to Affected Products |
54.0 | 20200819 | NetApp SolidFire & HCI Storage Node (Element Software) added to Software Versions and Fixes |
55.0 | 20210105 | NetApp Plug-in for Symantec NetBackup moved to Won't Fix status |
56.0 | 20210216 | AFF Baseboard Management Controller (BMC) - A700s added to Software Versions and Fixes |
57.0 | 20210304 | OnCommand Cloud Manager added to Software Versions and Fixes |
58.0 | 20220114 | StorageGRID9 (9.x and prior) moved to Won't Fix status, Final status |
This document is provided solely for informational purposes. All information is based upon NetApp’s current knowledge and understanding of the hardware and software products tested by NetApp, and the methodology and assumptions used by NetApp. NetApp is not responsible for any errors or omissions that may be contained herein, and no warranty, representation, or other legal commitment or obligation is being provided by NetApp. © 2024 NetApp, Inc. All rights reserved. No portions of this document may be reproduced without prior written consent of NetApp, Inc.