CVE-2016-6904: High severity netapp vasa provider for clustered data ontap vulnerability
Published Dec 11, 2017
·Updated
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.
Affected Software
1 affected component
NetApp Vasa Provider Clustered Data Ontap<=7.0
Event History
Dec 11, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2016-6904?
CVE-2016-6904 is a vulnerability found in versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1.
2
What is the severity of CVE-2016-6904?
The severity of CVE-2016-6904 is high with a severity value of 8.1.
3
How does CVE-2016-6904 affect Netapp Vasa Provider?
CVE-2016-6904 affects Netapp Vasa Provider versions prior to 7.0P1.
4
How does CVE-2016-6904 impact security?
CVE-2016-6904 allows an unauthenticated attacker to obtain authentication credentials.
5
Is there a fix for CVE-2016-6904?
Yes, the fix for CVE-2016-6904 is to update to version 7.0P1 or later of VASA Provider for Clustered Data ONTAP.