Plaintext Password Storage Vulnerability in E-Series SANtricity OS by NetApp
CVE-2022-23236
4.4MEDIUM
Summary
The E-Series SANtricity OS Controller Software from NetApp contains a vulnerability where the LDAP BIND password is stored in plaintext within a file. This file is accessible solely by privileged users, posing a significant risk of unauthorized access to sensitive information if the privileges of those users are compromised. Organizations using versions 11.40 through 11.70.2 should take immediate action to mitigate this risk by updating to secure versions and reviewing user privileges.
Affected Version(s)
E-Series SANtricity OS Controller Software 11.x 11.40 through 11.70.2
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved