Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitive
CVSS 7.5CVE-2019-5491Control plane, storage & DevOpscurated
Impact
An attacker with no account extracts sensitive information from the storage controller, which is useful both directly and as reconnaissance for a follow-on attack against the cluster.
Who can reach it
Network reach to a Clustered Data ONTAP system earlier than 9.1P15 or 9.3P7. No credentials required.
What to do
Upgrade to 9.1P15 / 9.3P7 or later. Restrict which networks can reach the controller's management and data LIFs while the upgrade is scheduled.
References
Related entries
- ntpd (NTP.org reference implementation): An off-path attacker can block a node's unauthenticated time synchronizationCVE-2020-11868 · ntpd (NTP.org reference implementation)High
- Ceph RADOS Gateway (RGW): A POST carrying malformed object-tagging XML dereferences a NULL pointer and kills theCVE-2020-12059 · Ceph RADOS Gateway (RGW)High
- Ceph dashboard (ceph-mgr dashboard module): An unauthenticated HTTP request with traversal sequences reads arbitraryCVE-2020-1699 · Ceph dashboard (ceph-mgr dashboard module)High
- IBM Elastic Storage System / Elastic Storage Server (UDP request handling): An unauthenticated attacker who can sendCVE-2020-5015 · IBM Elastic Storage System / Elastic Storage Server (UDP request handling)High
- NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removingCVE-2021-27005 · NetApp Clustered Data ONTAP httpdHigh
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.