CVE-2024-21985
Published: Jan 26, 2024
Modified: May 29, 2025
CVSS v3.1
7.6
Description
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited configuration details and metrics or modifying limited settings, some of which could result in a Denial of Service (DoS).
| Vendor | Product | Versions |
|---|---|---|
NetApp | ONTAP 9 | affected 9.0 - < 9.9.1P18affected 9.10.1 - < 9.10.1P16affected 9.11.1 - < 9.11.1P13affected 9.12.1 - < 9.12.1P10affected 9.13.1 - < 9.13.1P4 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now