CVE-2024-21982
MEDIUMNetApp Clustered Data ONTAP 9.4-9.8 - Unauthenticated Sensitive Information Disclosure via Object-Store Profiler Command
Title source: llmDescription
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
References (1)
Core 1
Core References
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240111-0001/
Scores
CVSS v3
4.8
EPSS
0.0037
EPSS Percentile
58.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (7)
netapp/clustered_data_ontap
9.8
netapp/clustered_data_ontap
9.9.1
netapp/clustered_data_ontap
9.10.1
netapp/clustered_data_ontap
9.11.1
netapp/clustered_data_ontap
9.12.1
netapp/clustered_data_ontap
9.13.1
netapp/clustered_data_ontap
9.4 - 9.8
Published
Jan 12, 2024
Tracked Since
Feb 18, 2026