GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code and

CVE-2019-5509Control plane, storage & DevOpscurated

Impact

An unauthenticated remote attacker injects code and enables a privileged account on the Deploy appliance, taking over provisioning for every ONTAP Select cluster it manages.

Who can reach it

Network access to ONTAP Select Deploy 2.11.2 through 2.12.2. No prior account needed.

What to do

Upgrade to a fixed Deploy release, then enumerate local accounts on the appliance and delete any privileged account you did not create. Rotate the credentials of the ones you keep.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.