PT-2024-19143 · Netapp · Ontap Select Deploy Administration Utility

Published

2024-04-17

·

Updated

2024-04-18

·

CVE-2024-21990

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x
Description The issue is related to hard-coded credentials in the affected software, which could allow an attacker to view configuration information and modify account credentials.
Recommendations For versions 9.12.1.x, consider removing or modifying the hard-coded credentials to prevent unauthorized access. For versions 9.13.1.x, restrict access to the Deploy configuration information until the hard-coded credentials are removed or modified. For versions 9.14.1.x, avoid using the default credentials and update them to unique, secure credentials to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-21990

Affected Products

Ontap Select Deploy Administration Utility