CVE-2024-21982

3 documents3 sources
Severity
6.5MEDIUM
EPSS
0.4%
top 41.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12

Description

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5netapp/ontap_99.49.8P21+5
NVDnetapp/clustered_data_ontap9.49.8+6

🔴Vulnerability Details

2
GHSA
GHSA-mr7g-4crw-jcpj: ONTAP versions 92024-01-12
CVEList
CVE-2024-21982 Information Disclosure Vulnerability in ONTAP 92024-01-11