GPU VulnDB

Database/Control plane, storage & DevOps

NetApp ONTAP Select Deploy administration utility (hard-coded credentials): MULTI-TENANT ISOLATION: baked-in

CVE-2024-21990Control plane, storage & DevOpscurated

Impact

MULTI-TENANT ISOLATION: baked-in credentials let an attacker read Deploy configuration and change account credentials, which hands over the management plane for every ONTAP Select cluster the appliance controls.

Who can reach it

Network reach to ONTAP Select Deploy 9.12.1.x, 9.13.1.x or 9.14.1.x. The credential ships with the product, so it is the same everywhere and is not something an operator can rotate away.

What to do

Upgrade Deploy to 9.15.1 or the fixed patch level NetApp names. Rotating passwords does not help while the hard-coded pair is present, so treat network isolation of the appliance as the only interim control.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.