Sensitive Information Disclosure via Complex MiTM Attacks

CVE-2024-21988
5.3MEDIUM

Key Information

Vendor
Netapp
Status
Storagegrid (formerly Storagegrid Webscale)
Vendor
CVE Published:
14 June 2024

Summary

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.

Affected Version(s)

StorageGRID (formerly StorageGRID Webscale) < 11.7.0.9

StorageGRID (formerly StorageGRID Webscale) < 11.8.0.5

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.