PT-2024-19143 · Netapp · Ontap Select Deploy Administration Utility
Published
2024-04-17
·
Updated
2024-04-18
·
CVE-2024-21990
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x
Description
The issue is related to hard-coded credentials in the affected software, which could allow an attacker to view configuration information and modify account credentials.
Recommendations
For versions 9.12.1.x, consider removing or modifying the hard-coded credentials to prevent unauthorized access.
For versions 9.13.1.x, restrict access to the Deploy configuration information until the hard-coded credentials are removed or modified.
For versions 9.14.1.x, avoid using the default credentials and update them to unique, secure credentials to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ontap Select Deploy Administration Utility