Remote Code Execution Vulnerability in ONTAP Select Deploy by NetApp
CVE-2019-5504
9.8CRITICAL
Summary
The ONTAP Select Deploy administration utility versions 2.12 and 2.12.1 are vulnerable due to an HTTP service that is exposed on the network. This misconfiguration allows unauthenticated remote attackers to execute administrative actions, potentially compromising the integrity and security of the system. Administrators are advised to secure their deployment to mitigate the risk of unauthorized access and control.
Affected Version(s)
ONTAP Select Deploy administration utility Versions 2.12 & 2.12.1
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved