GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP 9 role-based access control: A user holding several remote accounts with different roles performs actions

CVE-2024-21985Control plane, storage & DevOpscurated

Impact

A user holding several remote accounts with different roles performs actions none of those roles should permit, which defeats the separation between an operator who can read and one who can destroy.

Who can reach it

An authenticated ONTAP user with more than one remote account on a system below 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 or 9.13.1P4.

What to do

Upgrade to the fixed patch level. In the meantime, avoid granting the same person multiple ONTAP accounts with different roles, since that is the precondition.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.