PT-2022-15916 · Netapp · Clustered Data Ontap

Published

2022-10-19

·

Updated

2025-05-09

·

CVE-2022-23241

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Clustered Data ONTAP versions 9.11.1 through 9.11.1P2
Description The issue allows an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period, specifically in configurations with SnapLock and FlexGroups.
Recommendations For Clustered Data ONTAP versions 9.11.1 through 9.11.1P2, consider restricting access to SnapLock configured FlexGroups until a patch is available. As a temporary workaround, limit the privileges of authenticated remote attackers to prevent modification or deletion of WORM data. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-23241

Affected Products

Clustered Data Ontap