CVE-2022-23236

Severity CVSS v4.0:
Pending analysis
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
02/06/2022
Last modified:
11/06/2022

Description

E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:* 11.40 (including) 11.70.2 (including)


References to Advisories, Solutions, and Tools