CVE-2024-21985

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/01/2024
Last modified:
05/02/2024

Description

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 <br /> and 9.13.1P4 are susceptible to a vulnerability which could allow an <br /> authenticated user with multiple remote accounts with differing roles to<br /> perform actions via REST API beyond their intended privilege. Possible <br /> actions include viewing limited configuration details and metrics or <br /> modifying limited settings, some of which could result in a Denial of <br /> Service (DoS).<br /> <br /> <br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.0 (including) 9.9.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.10.0 (including) 9.10.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.11.0 (including) 9.11.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.12.0 (including) 9.12.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.13.0 (including) 9.13.1 (excluding)
cpe:2.3:a:netapp:clustered_data_ontap:9.9.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.10.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.11.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.12.1:-:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:9.13.1:-:*:*:*:*:*:*


References to Advisories, Solutions, and Tools