ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10
and 9.13.1P4 are susceptible to a vulnerability which could allow an
authenticated user with multiple remote accounts with differing roles to
perform actions via REST API beyond their intended privilege. Possible
actions include viewing limited configuration details and metrics or
modifying limited settings, some of which could result in a Denial of
Service (DoS).
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/ntap-20240126-0001/ | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240126-0001/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://security.netapp.com/advisory/ntap-20240126-0001/ - Vendor Advisory |
05 Feb 2024, 18:32
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.6 |
First Time |
Netapp clustered Data Ontap
Netapp |
|
References | () https://security.netapp.com/advisory/ntap-20240126-0001/ - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:netapp:clustered_data_ontap:9.9.1:-:*:*:*:*:*:* cpe:2.3:a:netapp:clustered_data_ontap:9.12.1:-:*:*:*:*:*:* cpe:2.3:a:netapp:clustered_data_ontap:9.10.1:-:*:*:*:*:*:* cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:clustered_data_ontap:9.13.1:-:*:*:*:*:*:* cpe:2.3:a:netapp:clustered_data_ontap:9.11.1:-:*:*:*:*:*:* |
26 Jan 2024, 16:33
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-26 16:15
Updated : 2024-11-21 08:55
NVD link : CVE-2024-21985
Mitre link : CVE-2024-21985
CVE.ORG link : CVE-2024-21985
JSON object : View
Products Affected
netapp
- clustered_data_ontap
CWE