Plaintext Password Storage Vulnerability in E-Series SANtricity OS by NetApp
CVE-2022-23236
4.4MEDIUM
What is CVE-2022-23236?
The E-Series SANtricity OS Controller Software from NetApp contains a vulnerability where the LDAP BIND password is stored in plaintext within a file. This file is accessible solely by privileged users, posing a significant risk of unauthorized access to sensitive information if the privileges of those users are compromised. Organizations using versions 11.40 through 11.70.2 should take immediate action to mitigate this risk by updating to secure versions and reviewing user privileges.
Affected Version(s)
E-Series SANtricity OS Controller Software 11.x 11.40 through 11.70.2