Data Exposure Vulnerability in NetApp Clustered Data ONTAP
CVE-2020-8590

3.3LOW

Key Information:

Vendor
Netapp
Vendor
CVE Published:
8 February 2021

Summary

Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 present a vulnerability that enables unauthorized users to potentially expose sensitive node names. This occurs through AutoSupport bundles, which might reveal information even when protective parameters, such as -remove-private-data, are appropriately configured. Timely updates to the latest versions are crucial to mitigate these risks and enhance system security.

Affected Version(s)

Clustered Data ONTAP Versions prior to 9.1P18 and 9.3P12

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-8590 : Data Exposure Vulnerability in NetApp Clustered Data ONTAP | SecurityVulnerability.io