Database/Control plane, storage & DevOps
NetApp ONTAP Select Deploy administration utility (hard-coded credentials): Baked-in credentials let an attacker read
Impact
Baked-in credentials let an attacker read Deploy configuration and change account credentials, which hands over the management plane for every ONTAP Select cluster the appliance controls.
Who can reach it
Network reach to ONTAP Select Deploy 9.12.1.x, 9.13.1.x or 9.14.1.x. The credential ships with the product, so it is the same everywhere and is not something an operator can rotate away.
What to do
Upgrade Deploy to 9.15.1 or the fixed patch level NetApp names. Rotating passwords does not help while the hard-coded pair is present, so treat network isolation of the appliance as the only interim control.
References
Related entries
- HPE Cray Parallel Application Launch Service (PALS) authentication bypass: Authentication bypass in the serviceCVE-2024-22441 · HPE Cray Parallel Application Launch Service (PALS) authentication bypassCritical
- Jenkins: CLI parser expands `@file` into argument contentsCVE-2024-23897 · JenkinsCritical
- LenelS2 NetBox access control and event monitoring system (<=5.6.1): Unauthenticated remote code executionCVE-2024-2421 · LenelS2 NetBox access control and event monitoring system (<=5.6.1)Critical
- JetBrains TeamCity: Alternative-path authentication bypassCVE-2024-27198 · JetBrains TeamCityCritical
- Veeam Backup Enterprise Manager: Unauthenticated users can log in as any user to the Enterprise Manager web interfaceCVE-2024-29849 · Veeam Backup Enterprise ManagerCritical
- CyberPower PowerPanel platform - hardcoded database, service and cloud credentials: Hardcoded credentials usedCVE-2024-32053 · CyberPower PowerPanel platform - hardcoded database, service and cloud credentialsCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.