Plaintext Password Storage Vulnerability in E-Series SANtricity OS by NetApp
CVE-2022-23236

4.4MEDIUM

Key Information:

Vendor
Netapp
Vendor
CVE Published:
2 June 2022

Summary

The E-Series SANtricity OS Controller Software from NetApp contains a vulnerability where the LDAP BIND password is stored in plaintext within a file. This file is accessible solely by privileged users, posing a significant risk of unauthorized access to sensitive information if the privileges of those users are compromised. Organizations using versions 11.40 through 11.70.2 should take immediate action to mitigate this risk by updating to secure versions and reviewing user privileges.

Affected Version(s)

E-Series SANtricity OS Controller Software 11.x 11.40 through 11.70.2

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-23236 : Plaintext Password Storage Vulnerability in E-Series SANtricity OS by NetApp | SecurityVulnerability.io