GPU VulnDB

Database/Control plane, storage & DevOps

NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removing

CVE-2021-27005Control plane, storage & DevOpscurated

Impact

A remote attacker with no credentials crashes the ONTAP web server, removing management and API access to the array until it recovers.

Who can reach it

Network path to httpd on Clustered Data ONTAP 9.6 and later below 9.6P16, 9.7P16, 9.8P7 or 9.9.1P3.

What to do

Upgrade to the fixed patch level and limit which subnets can reach the management LIF.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.