Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (code injection): An unauthenticated remote attacker injects code and
CVSS 9.8CVE-2019-5509Control plane, storage & DevOpscurated
Impact
An unauthenticated remote attacker injects code and enables a privileged account on the Deploy appliance, taking over provisioning for every ONTAP Select cluster it manages.
Who can reach it
Network access to ONTAP Select Deploy 2.11.2 through 2.12.2. No prior account needed.
What to do
Upgrade to a fixed Deploy release, then enumerate local accounts on the appliance and delete any privileged account you did not create. Rotate the credentials of the ones you keep.
References
Related entries
- Slurm (32-bit RPC handling): Memory corruption on 32-bit Slurm builds reachable from a crafted RPC, up to control ofCVE-2019-6438 · Slurm (32-bit RPC handling)Critical
- Optergy Proton / Enterprise building management platform: A backdoor console giving remote root code executionCVE-2019-7276 · Optergy Proton / Enterprise building management platformCritical
- Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra service: Unauthenticated remote code executionCVE-2019-9569 · Delta Controls enteliBUS Manager (eBMGR) V3.40_B-571848, dactetra serviceCritical
- Fortinet FortiOS SSL-VPN: A logic flaw lets a user who changes their login case (e.gCVE-2020-12812 · Fortinet FortiOS SSL-VPNCritical
- Brocade Fabric OS REST API: Multiple buffer overflows in the Fabric OS REST API reachable by an unauthenticated remoteCVE-2020-15373 · Brocade Fabric OS REST APICritical
- Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management): The earlier cluster on the same consoleCVE-2020-15639 · Marvell QConvergeConsole GUI 5.5.0.64 - 5.5.0.74 (QLogic HBA management)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.