Remote Code Execution Vulnerability in ONTAP Select Deploy by NetApp
CVE-2019-5504

9.8CRITICAL

Key Information:

Vendor
Netapp
Vendor
CVE Published:
24 September 2019

Summary

The ONTAP Select Deploy administration utility versions 2.12 and 2.12.1 are vulnerable due to an HTTP service that is exposed on the network. This misconfiguration allows unauthenticated remote attackers to execute administrative actions, potentially compromising the integrity and security of the system. Administrators are advised to secure their deployment to mitigate the risk of unauthorized access and control.

Affected Version(s)

ONTAP Select Deploy administration utility Versions 2.12 & 2.12.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-5504 : Remote Code Execution Vulnerability in ONTAP Select Deploy by NetApp | SecurityVulnerability.io