PT-2024-2526 · Netapp · Netapp Snapcenter
Published
2024-02-16
·
Updated
2024-12-16
·
CVE-2024-21987
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
NetApp SnapCenter versions 4.8 prior to 5.0
Description
The issue is related to insufficient authorization in the NetApp SnapCenter platform, allowing a remote attacker to modify system logging configuration settings. This can be done by an authenticated SnapCenter Server user.
Recommendations
For NetApp SnapCenter versions 4.8 prior to 5.0, update to version 5.0 or later to resolve the issue. As a temporary workaround, consider restricting access to system logging configuration settings until a patch is available.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netapp Snapcenter