Data Integrity Vulnerability in NetApp Clustered Data ONTAP Software
CVE-2021-27001

5.5MEDIUM

Key Information:

Vendor
Netapp
Vendor
CVE Published:
19 October 2021

Summary

The vulnerability in NetApp Clustered Data ONTAP versions allows authenticated privileged local attackers to alter Compliance-mode WORM data, compromising data integrity before the end of the designated retention period. This could lead to unauthorized changes to sensitive information, impacting compliance and data governance efforts.

Affected Version(s)

Clustered Data ONTAP 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2021-27001 : Data Integrity Vulnerability in NetApp Clustered Data ONTAP Software | SecurityVulnerability.io