cbcvebase.

Netapp Ontap vulnerabilities

24 known vulnerabilities affecting netapp/ontap.

Total CVEs
24
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH10MEDIUM8LOW3

Vulnerabilities

Page 2 of 2
CVE-2023-27317P4MEDIUMCVSS 4.6v9.12.1v9.13.12023-12-15
CVE-2023-27317 [MEDIUM] CWE-200 CVE-2023-27317: ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cau ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked after a system reboot or power cycle or a single SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This could lead to disclosure of sensitive information to an attacker with phys
nvd
CVE-2024-2004P4LOWCVSS 3.5v92024-03-27
CVE-2024-2004 [LOW] CWE-436 CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the defaul When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.s
nvd
CVE-2024-11053P4LOWCVSS 3.4v92024-12-11
CVE-2024-11053 [LOW] CVE-2024-11053: When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has an entry that matches the redirect target hostname but the entry either omits just the password or omits both login
nvd
CVE-2025-0167P4LOWCVSS 3.4v92025-02-05
CVE-2025-0167 [LOW] CVE-2025-0167: When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance.
nvd
Netapp Ontap vulnerabilities | cvebase