CVE-2022-23241

HIGH

Clustered Data ONTAP 9.11.1-9.11.1P2 - Authenticated WORM Data Modification and Deletion

Title source: llm
STIX 2.1

Description

Clustered Data ONTAP versions 9.11.1 through 9.11.1P2 with SnapLock configured FlexGroups are susceptible to a vulnerability which could allow an authenticated remote attacker to arbitrarily modify or delete WORM data prior to the end of the retention period.

References (1)

Core 1

Scores

CVSS v3 8.1
EPSS 0.0035
EPSS Percentile 57.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
netapp/clustered_data_ontap 9.11.1 (3 CPE variants)
Published Oct 19, 2022
Tracked Since Feb 18, 2026