GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP Select Deploy administration utility (credential transport): Deploy sends its credentials in plaintext, so

CVE-2019-5505Control plane, storage & DevOpscurated

Impact

Deploy sends its credentials in plaintext, so anyone able to observe management traffic recovers the account that provisions and controls ONTAP Select storage clusters.

Who can reach it

A passive position on any network segment carrying Deploy management traffic - a mirrored port, a compromised switch, or a shared management VLAN.

What to do

Upgrade ONTAP Select Deploy 2.2 through 2.12.1 to a fixed release, then rotate every credential that was ever used with the affected versions. Assume anything on that wire is already known.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.