CVE-2024-21982 Information Disclosure Vulnerability in ONTAP 9
CVE-2024-21982

4.8MEDIUM

Key Information:

Vendor
NetApp
Status
Vendor
CVE Published:
12 January 2024

Summary

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.

Affected Version(s)

ONTAP 9 9.4 < 9.8P21

ONTAP 9 9.9.1 < 9.9.1P18

ONTAP 9 9.10.1 < 9.10.1P16

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-21982 : CVE-2024-21982 Information Disclosure Vulnerability in ONTAP 9 | SecurityVulnerability.io