CVE-2024-21985
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/01/2024
Last modified:
05/02/2024
Description
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 <br />
and 9.13.1P4 are susceptible to a vulnerability which could allow an <br />
authenticated user with multiple remote accounts with differing roles to<br />
perform actions via REST API beyond their intended privilege. Possible <br />
actions include viewing limited configuration details and metrics or <br />
modifying limited settings, some of which could result in a Denial of <br />
Service (DoS).<br />
<br />
<br />
<br />
Impact
Base Score 3.x
7.60
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* | 9.0 (including) | 9.9.1 (excluding) |
| cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* | 9.10.0 (including) | 9.10.1 (excluding) |
| cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* | 9.11.0 (including) | 9.11.1 (excluding) |
| cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* | 9.12.0 (including) | 9.12.1 (excluding) |
| cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* | 9.13.0 (including) | 9.13.1 (excluding) |
| cpe:2.3:a:netapp:clustered_data_ontap:9.9.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:clustered_data_ontap:9.10.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:clustered_data_ontap:9.11.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:clustered_data_ontap:9.12.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:netapp:clustered_data_ontap:9.13.1:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



