Data Exposure Vulnerability in NetApp Clustered Data ONTAP
CVE-2020-8590
3.3LOW
Summary
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 present a vulnerability that enables unauthorized users to potentially expose sensitive node names. This occurs through AutoSupport bundles, which might reveal information even when protective parameters, such as -remove-private-data, are appropriately configured. Timely updates to the latest versions are crucial to mitigate these risks and enhance system security.
Affected Version(s)
Clustered Data ONTAP Versions prior to 9.1P18 and 9.3P12
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved