CVE-2020-8585

MEDIUM

OnCommand Unified Manager Core Package <5.2.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20210128-0001/

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 33.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-59
Status published
Products (1)
netapp/oncommand_unified_manager < 5.2.5
Published Jan 28, 2021
Tracked Since Feb 18, 2026