CVE-2021-27001

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/10/2021
Last modified:
12/07/2022

Description

Clustered Data ONTAP versions 9.x prior to 9.5P18, 9.6P16, 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow an authenticated privileged local attacker to arbitrarily modify Compliance-mode WORM data prior to the end of the retention period.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* 9.0 (including) 9.4 (including)
cpe:2.3:o:netapp:clustered_data_ontap:9.5:-:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p12:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p13:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p14:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p15:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p16:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p17:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p6:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p8:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.5:p9:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.6:-:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.6:p1:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.6:p12:*:*:*:*:*:*
cpe:2.3:o:netapp:clustered_data_ontap:9.6:p15:*:*:*:*:*:*


References to Advisories, Solutions, and Tools