Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, so
CVSS 9.8CVE-2019-5505Control plane, storage & DevOpscurated
Impact
Deploy sends its credentials in plaintext, so anyone able to observe management traffic recovers the account that provisions and controls ONTAP Select storage clusters.
Who can reach it
A passive position on any network segment carrying Deploy management traffic - a mirrored port, a compromised switch, or a shared management VLAN.
What to do
Upgrade ONTAP Select Deploy 2.2 through 2.12.1 to a fixed release, then rotate every credential that was ever used with the affected versions. Assume anything on that wire is already known.
References
Related entries
- NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code andCVE-2019-5509 · NetApp ONTAP Select Deploy administration utility (code injection)Critical
- Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCVE-2019-6438 · Slurm (32-bit RPC handling)Critical
- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCVE-2019-7276 · Optergy Proton / Enterprise building management platformCritical
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCVE-2019-9569 · Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra serviceCritical
- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCVE-2020-12812 · Fortinet FortiOS SSL-VPNCritical
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCVE-2020-15373 · Brocade Fabric OS REST APICritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.