cbcvebase.

Netapp Clustered Data Ontap vulnerabilities

46 known vulnerabilities affecting netapp/clustered_data_ontap.

Total CVEs
46
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH18MEDIUM20LOW5

Vulnerabilities

Page 2 of 3
CVE-2023-36054P4MEDIUMCVSS 6.5v9.02023-08-07
CVE-2023-36054 [MEDIUM] CWE-824 CVE-2023-36054: lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees a lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
nvd
CVE-2017-5988P4HIGHCVSS 7.5v8.1v8.1.1+13 more2017-04-10
CVE-2017-5988 [HIGH] CVE-2017-5988: NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers t NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2019-5508P4HIGHCVSS 7.5≥ 9.2, ≤ 9.4v9.2 and higher2019-10-25
CVE-2019-5508 [HIGH] CVE-2019-5508: Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an att Clustered Data ONTAP versions 9.2 through 9.4 are susceptible to a vulnerability which allows an attacker to use l2ping to cause a Denial of Service (DoS).
nvd
CVE-2023-23915P4MEDIUMCVSS 6.5v9.02023-02-23
CVE-2023-23915 [MEDIUM] CWE-319 CVE-2023-23915: A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could c A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS
nvd
CVE-2024-21982P4MEDIUMCVSS 6.5≥ 9.4, < 9.8v9.8+5 more2024-01-12
CVE-2024-21982 [MEDIUM] CVE-2024-21982: ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
nvd
CVE-2016-3064P4MEDIUMCVSS 6.5≤ 8.2.4v8.3+2 more2016-09-01
CVE-2016-3064 [MEDIUM] CWE-200 CVE-2016-3064: NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated user NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors.
nvd
CVE-2017-7947P4MEDIUMCVSS 6.5v8.3.2v9.0+1 more2017-07-17
CVE-2017-7947 [MEDIUM] CWE-200 CVE-2017-7947: NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obt NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
nvd
CVE-2016-3997P4HIGHCVSS 7.5v8.3.12017-07-03
CVE-2016-3997 [HIGH] CWE-254 CVE-2016-3997: NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
nvd
CVE-2023-27537P4MEDIUMCVSS 5.9v9.02023-03-30
CVE-2023-27537 [MEDIUM] CWE-415 CVE-2023-27537: A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handle A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end
nvd
CVE-2023-27538P4MEDIUMCVSS 5.5v9.02023-03-30
CVE-2023-27538 [MEDIUM] CWE-305 CVE-2023-27538: An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previousl An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previously used connections to reuse them for subsequent transfers if the configurations match. However, two
nvd
CVE-2017-7345P4MEDIUMCVSS 5.3≤ 7.12017-04-10
CVE-2017-7345 [MEDIUM] CWE-200 CVE-2017-7345: NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7 NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors.
nvd
CVE-2016-1563P4MEDIUMCVSS 6.8v8.3.12016-04-07
CVE-2016-1563 [MEDIUM] CWE-20 CVE-2016-1563: NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, whic NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
nvd
CVE-2021-26994P4MEDIUMCVSS 6.5fixed in 9.7v9.7+2 more2021-06-04
CVE-2021-26994 [MEDIUM] CVE-2021-26994: Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which cou Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node.
nvd
CVE-2017-14583P4MEDIUMCVSS 6.5≥ 9.0, ≤ 9.1v9.22017-12-18
CVE-2017-14583 [MEDIUM] CWE-20 CVE-2017-14583: NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerabilit NetApp Clustered Data ONTAP versions 9.x prior to 9.1P10 and 9.2P2 are susceptible to a vulnerability which allows an attacker to cause a Denial of Service (DoS) in SMB environments.
nvd
CVE-2019-5506P4MEDIUMCVSS 5.9≥ 9.0, ≤ 9.6v9.6+1 more2019-10-09
CVE-2019-5506 [MEDIUM] CWE-295 CVE-2019-5506: Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circ Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.
nvd
CVE-2020-8576P4MEDIUMCVSS 5.4v9.3v9.5+4 more2020-09-02
CVE-2020-8576 [MEDIUM] CVE-2020-8576: Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerabil Clustered Data ONTAP versions prior to 9.3P19, 9.5P14, 9.6P9 and 9.7 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or disclosure of sensitive information.
nvd
CVE-2017-5201P4MEDIUMCVSS 5.7fixed in 8.3.2v9.02017-11-10
CVE-2017-5201 [MEDIUM] CVE-2017-5201: NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obt NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors, a different vulnerability than CVE-2016-3064.
nvd
CVE-2021-27001P4MEDIUMCVSS 5.5≥ 9.0, ≤ 9.4v9.5+5 more2021-10-19
CVE-2021-27001 [MEDIUM] CVE-2021-27001: Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.
nvd
CVE-2021-27003P4MEDIUMCVSS 4.7fixed in 9.5v9.5+4 more2021-10-12
CVE-2021-27003 [MEDIUM] CWE-1021 CVE-2021-27003: Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Fram Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X-Frame-Options header which could allow a clickjacking attack.
nvd
CVE-2018-5498P4MEDIUMCVSS 4.4≥ 9.0, ≤ 9.4vVersions 9.0 and higher2019-02-01
CVE-2018-5498 [MEDIUM] CWE-20 CVE-2018-5498: Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerability will allow a remote authenticated attacker to cause a Denial of Service (DoS) on affected versions of clustered Data ONTAP configu
nvd
Netapp Clustered Data Ontap vulnerabilities | cvebase