Database/Control plane, storage & DevOps
NetApp Clustered Data ONTAP httpd: A remote attacker with no credentials crashes the ONTAP web server, removing
CVE-2021-27005Control plane, storage & DevOpscurated
Impact
A remote attacker with no credentials crashes the ONTAP web server, removing management and API access to the array until it recovers.
Who can reach it
Network path to httpd on Clustered Data ONTAP 9.6 and later below 9.6P16, 9.7P16, 9.8P7 or 9.9.1P3.
What to do
Upgrade to the fixed patch level and limit which subnets can reach the management LIF.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.