PT-2021-12795 · Netapp · Clustered Data Ontap
Published
2021-02-08
·
Updated
2021-02-12
·
CVE-2020-8578
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Clustered Data ONTAP versions prior to 9.3P20
Description:
The issue allows an attacker to discover node names via AutoSupport bundles even when the
–remove-private-data parameter is set to true. This could potentially expose sensitive information.Recommendations:
For Clustered Data ONTAP versions prior to 9.3P20, update to version 9.3P20 or later to resolve the issue. As a temporary workaround, consider restricting access to AutoSupport bundles to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clustered Data Ontap