Netapp Clustered Data Ontap vulnerabilities
49 known vulnerabilities affecting netapp/clustered_data_ontap.
Total CVEs
49
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH19MEDIUM21LOW6
Vulnerabilities
Page 2 of 3
CVE-2021-26988LOWCVSS 3.5vPrior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.82021-03-04
CVE-2021-26988 [LOW] CVE-2021-26988: Clustered Data ONTAP versions prior to 9
Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P8 and 9.8 are susceptible to a vulnerability which could allow unauthorized tenant users to discover information related to converting a 7-Mode directory to Cluster-mode such as Storage Virtual Machine (SVM) names, volume names, directory paths and Job IDs.
cvelistv5
CVE-2020-8590LOWCVSS 3.3fixed in 9.1≥ 9.2, < 9.3+3 more2021-02-08
CVE-2020-8590 [LOW] CVE-2020-8590: Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which co
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
cvelistv5nvd
CVE-2020-8578LOWCVSS 3.3fixed in 9.3v9.3+1 more2021-02-08
CVE-2020-8578 [LOW] CVE-2020-8578: Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow a
Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
cvelistv5nvd
CVE-2020-8588LOWCVSS 3.5fixed in 9.3≥ 9.4, < 9.5+3 more2021-02-03
CVE-2020-8588 [LOW] CVE-2020-8588: Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which co
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the existence of data on other Storage Virtual Machines (SVMs).
cvelistv5nvd
CVE-2020-8589LOWCVSS 3.5fixed in 9.3≥ 9.4, < 9.5+3 more2021-02-03
CVE-2020-8589 [LOW] CVE-2020-8589: Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which co
Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are susceptible to a vulnerability which could allow unauthorized tenant users to discover the names of other Storage Virtual Machines (SVMs) and filenames on those SVMs.
cvelistv5nvd
CVE-2020-8581MEDIUMCVSS 6.5fixed in 9.3≥ 9.4, ≤ 9.5+2 more2021-01-19
CVE-2020-8581 [MEDIUM] CVE-2020-8581: Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could
Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are susceptible to a vulnerability which could allow an authenticated but unauthorized attacker to overwrite arbitrary data when VMware vStorage support is enabled.
cvelistv5nvd
CVE-2020-8579HIGHCVSS 7.5v9.7v9.7 through 9.7P72020-10-27
CVE-2020-8579 [HIGH] CVE-2020-8579: Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an a
Clustered Data ONTAP versions 9.7 through 9.7P7 are susceptible to a vulnerability which allows an attacker with access to an intercluster LIF to cause a Denial of Service (DoS).
cvelistv5nvd
CVE-2020-8576MEDIUMCVSS 5.4v9.3v9.5+4 more2020-09-02
CVE-2020-8576 [MEDIUM] CVE-2020-8576: Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerabil
Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or disclosure of sensitive information.
cvelistv5nvd
CVE-2019-5508HIGHCVSS 7.5≥ 9.2, ≤ 9.4v9.2 and higher2019-10-25
CVE-2019-5508 [HIGH] CVE-2019-5508: Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an att
Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS).
cvelistv5nvd
CVE-2019-5506MEDIUMCVSS 5.9≥ 9.0, ≤ 9.6v9.6+1 more2019-10-09
CVE-2019-5506 [MEDIUM] CWE-295 CVE-2019-5506: Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circ
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.
cvelistv5nvd
CVE-2019-10092MEDIUMCVSS 6.1PoC≤ 9.5v9.62019-09-26
CVE-2019-10092 [MEDIUM] CWE-79 CVE-2019-10092: In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but was misconfigured in such a way that
nvd
CVE-2019-8936HIGHCVSS 7.5fixed in 9.22019-05-15
CVE-2019-8936 [HIGH] CWE-476 CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference.
NTP through 4.2.8p12 has a NULL Pointer Dereference.
nvd
CVE-2019-5491HIGHCVSS 7.5≥ 9.0, < 9.1v9.1+2 more2019-02-27
CVE-2019-5491 [HIGH] CVE-2019-5491: Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerabil
Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthenticated user.
cvelistv5nvd
CVE-2018-5498MEDIUMCVSS 4.4≥ 9.0, ≤ 9.4vVersions 9.0 and higher2019-02-01
CVE-2018-5498 [MEDIUM] CWE-20 CVE-2018-5498: Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerability will allow a remote authenticated attacker to cause a Denial of Service (DoS) on affected versions of clustered Data ONTAP configu
cvelistv5nvd
CVE-2018-5497MEDIUMCVSS 4.4≤ 9.1v9.1+3 more2019-01-24
CVE-2018-5497 [MEDIUM] CWE-200 CVE-2018-5497: Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability w
Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user.
cvelistv5nvd
CVE-2018-5490HIGHCVSS 8.8fixed in 8.3v8.3 Release Candidate versions2018-08-03
CVE-2018-5490 [HIGH] CWE-732 CVE-2018-5490: Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candida
Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the N
cvelistv5nvd
CVE-2017-14583MEDIUMCVSS 6.5≥ 9.0, ≤ 9.1v9.22017-12-18
CVE-2017-14583 [MEDIUM] CWE-20 CVE-2017-14583: NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerabilit
NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in SMB environments.
nvd
CVE-2017-5201MEDIUMCVSS 5.7fixed in 8.3.2v9.02017-11-10
CVE-2017-5201 [MEDIUM] CVE-2017-5201: NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obt
NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors, a different vulnerability than CVE-2016-3064.
nvd
CVE-2017-12421HIGHCVSS 8.8v8.3v8.3.1+2 more2017-09-01
CVE-2017-12421 [HIGH] CVE-2017-12421: NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbit
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to execute arbitrary code on the storage controller via unspecified vectors.
nvd
CVE-2017-12423HIGHCVSS 7.7v8.3v8.3.1+2 more2017-09-01
CVE-2017-12423 [HIGH] CVE-2017-12423: NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on
NetApp Clustered Data ONTAP 8.3.x before 8.3.2P12 allows remote authenticated users to read data on other Storage Virtual Machines (SVMs) via unspecified vectors.
nvd