CVE-2016-5374: High severity NetApp Data ONTAP vulnerability
Published Mar 1, 2017
·Updated
NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging improper handling of the ownerrights ACL entry.
Affected Software
2 affected components
NetApp Data ONTAP=9.0
NetApp Data ONTAP=9.1
Remediation
Event History
Mar 1, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-5374?
CVE-2016-5374 has a CVSS score indicating a high severity level, primarily affecting data confidentiality.
2
How do I fix CVE-2016-5374?
To mitigate CVE-2016-5374, upgrade NetApp Data ONTAP to version 9.1P1 or later.
3
Who is affected by CVE-2016-5374?
CVE-2016-5374 affects remote authenticated users who own data hosted on SMB shares in specific versions of NetApp Data ONTAP.
4
What type of vulnerability is CVE-2016-5374?
CVE-2016-5374 is an access control vulnerability that allows unauthorized sharing of SMB-hosted data.
5
When was CVE-2016-5374 published?
CVE-2016-5374 was published in August 2016.