Netapp Clustered Data Ontap vulnerabilities
46 known vulnerabilities affecting netapp/clustered_data_ontap.
Total CVEs
46
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH18MEDIUM20LOW5
Vulnerabilities
Page 1 of 3
CVE-2019-10092P3MEDIUMCVSS 6.1PoC≤ 9.5v9.62019-09-26
CVE-2019-10092 [MEDIUM] CWE-79 CVE-2019-10092: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that
nvd
CVE-2024-38476P2CRITICALCVSS 9.8v9.02024-07-01
CVE-2024-38476 [CRITICAL] CWE-829 CVE-2024-38476: Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclos
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2024-38474P3CRITICALCVSS 9.8v9.02024-07-01
CVE-2024-38474 [CRITICAL] CWE-116 CVE-2024-38474: Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in
directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2023-27533P3HIGHCVSS 8.8v9.02023-03-30
CVE-2023-27533 [HIGH] CWE-75 CVE-2023-27533: A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protoc
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This v
nvd
CVE-2017-12421P3HIGHCVSS 8.8v8.3v8.3.1+2 more2017-09-01
CVE-2017-12421 [HIGH] CVE-2017-12421: NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbit
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors.
nvd
CVE-2017-12420P3HIGHCVSS 8.8≤ 8.3.2≤ 9.02017-08-18
CVE-2017-12420 [HIGH] CWE-119 CVE-2017-12420: Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 a
Heap-based buffer overflow in the SMB implementation in NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allows remote authenticated users to cause a denial of service or execute arbitrary code.
nvd
CVE-2024-38477P3HIGHCVSS 7.5v9.02024-07-01
CVE-2024-38477 [HIGH] CWE-476 CVE-2024-38477: null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to
null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
nvd
CVE-2022-23241P3HIGHCVSS 8.1v9.11.1v9.11.1 through 9.11.1P22022-10-19
CVE-2022-23241 [HIGH] CWE-284 CVE-2022-23241: Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are suscep
Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period.
nvd
CVE-2023-23914P3CRITICALCVSS 9.1v9.02023-02-23
CVE-2023-23914 [CRITICAL] CWE-319 CVE-2023-23914: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could c
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would howe
nvd
CVE-2024-21985P3HIGHCVSS 7.6≥ 9.0, < 9.9.1≥ 9.10.0, < 9.10.1+8 more2024-01-26
CVE-2024-21985 [HIGH] CWE-269 CVE-2024-21985: ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10
and 9.13.1P4 are susceptible to a vulnerability which could allow an
authenticated user with multiple remote accounts with differing roles to
perform actions via REST API beyond their intended privilege. Possible
actions include viewing limited configuration details and metrics or
modi
nvd
CVE-2018-5490P3HIGHCVSS 8.8fixed in 8.3v8.3 Release Candidate versions2018-08-03
CVE-2018-5490 [HIGH] CWE-732 CVE-2018-5490: Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candida
Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the N
nvd
CVE-2019-5491P3HIGHCVSS 7.5≥ 9.0, < 9.1v9.1+2 more2019-02-27
CVE-2019-5491 [HIGH] CVE-2019-5491: Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerabil
Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthenticated user.
nvd
CVE-2023-27314P3HIGHCVSS 7.5≥ 9.0, < 9.8v9.8+5 more2023-10-12
CVE-2023-27314 [HIGH] CWE-400 CVE-2023-27314: ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8, 9.12.1P2 and 9.13.1 are susceptibl
ONTAP 9 versions prior to 9.8P19, 9.9.1P16, 9.10.1P12, 9.11.1P8,
9.12.1P2 and 9.13.1 are susceptible to a vulnerability which could allow
a remote unauthenticated attacker to cause a crash of the HTTP service.
nvd
CVE-2023-38403P3HIGHCVSS 7.5v9.02023-07-17
CVE-2023-38403 [HIGH] CWE-190 CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted lengt
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
nvd
CVE-2016-4341P3HIGHCVSS 7.5≤ 8.3.22017-02-07
CVE-2016-4341 [HIGH] CWE-200 CVE-2016-4341: NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information v
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.
nvd
CVE-2019-8936P3HIGHCVSS 7.5fixed in 9.22019-05-15
CVE-2019-8936 [HIGH] CWE-476 CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference.
NTP through 4.2.8p12 has a NULL Pointer Dereference.
nvd
CVE-2020-8581P3MEDIUMCVSS 6.5fixed in 9.3≥ 9.4, ≤ 9.5+2 more2021-01-19
CVE-2020-8581 [MEDIUM] CVE-2020-8581: Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
nvd
CVE-2020-8579P3HIGHCVSS 7.5v9.7v9.7 through 9.7P72020-10-27
CVE-2020-8579 [HIGH] CVE-2020-8579: Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an a
Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access to an intercluster LIF to cause a Denial of Service (DoS).
nvd
CVE-2017-12423P3HIGHCVSS 7.7v8.3v8.3.1+2 more2017-09-01
CVE-2017-12423 [HIGH] CVE-2017-12423: NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vectors.
nvd
CVE-2023-3107P3HIGHCVSS 7.5v9.02023-08-01
CVE-2023-3107 [HIGH] CWE-190 CVE-2023-3107: A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a frag
A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
nvd
1 / 3Next →