Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP (unauthenticated information disclosure): An attacker with no account extracts sensitive
CVE-2019-5491Control plane, storage & DevOpscurated
Impact
An attacker with no account extracts sensitive information from the storage controller, which is useful both directly and as reconnaissance for a follow-on attack against the cluster.
Who can reach it
Network reach to a Clustered Data ONTAP system earlier than 9.1P15 or 9.3P7. No credentials required.
What to do
Upgrade to 9.1P15 / 9.3P7 or later. Restrict which networks can reach the controller's management and data LIFs while the upgrade is scheduled.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.