CVE Database
/

CVE-2024-21985

Back to search

CVE-2024-21985

Published: Jan 26, 2024

Modified: May 29, 2025

PUBLISHED

CVSS v3.1

7.6

HIGH

Description

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited configuration details and metrics or modifying limited settings, some of which could result in a Denial of Service (DoS).

VendorProductVersions

NetApp

ONTAP 9

affected
9.0 - < 9.9.1P18
affected
9.10.1 - < 9.10.1P16
affected
9.11.1 - < 9.11.1P13
affected
9.12.1 - < 9.12.1P10
affected
9.13.1 - < 9.13.1P4

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now