PT-2024-3870 · Netapp · Ontap

Published

2024-01-11

·

Updated

2024-01-18

·

CVE-2024-21982

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: ONTAP versions 9.4 and higher
Description: The issue is related to the Object-Store Profiler Command Handler component in the Clustered Data ONTAP operating system for data storage systems. It involves the disclosure of sensitive information during data transmission. When exploited, this could allow a remote attacker to gain unauthorized access to protected information by executing commands with administrative privileges. The vulnerability can be exploited when the object-store profiler command is run by an administrative user.
Recommendations: For ONTAP versions 9.4 and higher, consider restricting access to the object-store profiler command to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the execution of commands with administrative privileges to necessary cases only. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04271
CVE-2024-21982

Affected Products

Ontap