Sensitive Information Disclosure via Complex MiTM Attacks
CVE-2024-21988

5.3MEDIUM

Key Information:

Vendor
Netapp
Status
Storagegrid (formerly Storagegrid Webscale)
Vendor
CVE Published:
14 June 2024

Summary

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.

Affected Version(s)

StorageGRID (formerly StorageGRID Webscale) 0 < 11.7.0.9

StorageGRID (formerly StorageGRID Webscale) 0 < 11.8.0.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.