Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removing
CVSS 7.5CVE-2021-27005Control plane, storage & DevOpscurated
Impact
A remote attacker with no credentials crashes the ONTAP web server, removing management and API access to the array until it recovers.
Who can reach it
Network path to httpd on Clustered Data ONTAP 9.6 and later below 9.6P16, 9.7P16, 9.8P7 or 9.9.1P3.
What to do
Upgrade to the fixed patch level and limit which subnets can reach the management LIF.
References
Related entries
- SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01): A zero-length PDU sent where data is expectedCVE-2021-28361 · SPDK iSCSI target (before 20.01.01) and SPDK vhost target (before 19.01)High
- Grafana: Unauthenticated directory traversal via /public/plugins/<id>/CVE-2021-43798 · GrafanaHigh
- Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05CVE-2021-45454 · Ampere Altra before SRP 1.08b and Altra Max before SRP 2.05 - power telemetry exposed through the Linux HWmon interfaceHigh
- Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi): Unauthenticated arbitrary file read off the gatewayCVE-2022-37122 · Carel pCOWeb HVAC BACnet gateway 2.1.0 (logdownload.cgi)High
- FlyteAdmin (built-in OAuth authorization server, default client secret hashes): Turning on Flyte's built-inCVE-2022-39273 · FlyteAdmin (built-in OAuth authorization server, default client secret hashes)High
- IBM Storage Scale Container Native Storage Access (network namespace exposure): Hosts outside the cluster can openCVE-2022-41738 · IBM Storage Scale Container Native Storage Access (network namespace exposure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.