← Back

CVE-2024-21985

nvd nist
Published: Jan 26, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Exploitability: 2.8 / Impact: 4.7
Source: NVD

Description

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited configuration details and metrics or modifying limited settings, some of which could result in a Denial of Service (DoS).

Affected (10)

1 product
Clustered Data Ontap
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
From 9.0 to 9.9.1
From 9.10.0 to 9.10.1
From 9.11.0 to 9.11.1
From 9.12.0 to 9.12.1
From 9.13.0 to 9.13.1
Version 9.10.1
Version 9.11.1
Version 9.12.1
Version 9.13.1
Version 9.9.1

References (2)

Source: security-alert@netapp.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.