CVE-2016-6904

Severity CVSS v4.0:
Pending analysis
Type:
CWE-255 Credentials Management
Publication date:
11/12/2017
Last modified:
20/04/2025

Description

Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netapp:vasa_provider:*:*:*:*:*:clustered_data_ontap:*:* 7.0 (including)