CVE-2016-3400: High severity NetApp Data ONTAP vulnerability
Published Jul 3, 2017
·Updated
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
Affected Software
2 affected components
NetApp Data ONTAP=8.1
NetApp Data ONTAP=8.2
Event History
Jul 3, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-3400?
The severity of CVE-2016-3400 is rated high with a score of 7.5.
2
How do I fix CVE-2016-3400?
To fix CVE-2016-3400, it is recommended to update NetApp Data ONTAP to a version beyond 8.2 that is not operating in 7-Mode.
3
What are the risks associated with CVE-2016-3400?
CVE-2016-3400 allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service.
4
Which versions of NetApp Data ONTAP are affected by CVE-2016-3400?
CVE-2016-3400 affects NetApp Data ONTAP versions 8.1 and 8.2 when operating in 7-Mode.
5
What type of vulnerability is CVE-2016-3400 classified as?
CVE-2016-3400 is classified as a vulnerability related to improper access control, specifically identified as CWE-254.