PT-2022-15916 · Netapp · Clustered Data Ontap
Published
2022-10-19
·
Updated
2025-05-09
·
CVE-2022-23241
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Clustered Data ONTAP versions 9.11.1 through 9.11.1P2
Description
The issue allows an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period, specifically in configurations with SnapLock and FlexGroups.
Recommendations
For Clustered Data ONTAP versions 9.11.1 through 9.11.1P2, consider restricting access to SnapLock configured FlexGroups until a patch is available.
As a temporary workaround, limit the privileges of authenticated remote attackers to prevent modification or deletion of WORM data.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clustered Data Ontap