CVE-2017-7947: Infoleak
Published Jul 17, 2017
·Updated
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
Affected Software
3 affected components
NetApp Clustered Data ONTAP=8.3.2-p10
NetApp Clustered Data ONTAP=9.0-p3
NetApp Clustered Data ONTAP=9.1-p4
Event History
Jul 17, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-7947?
CVE-2017-7947 is classified as a medium severity vulnerability.
2
How do I fix CVE-2017-7947?
To fix CVE-2017-7947, upgrade to versions 8.3.2P11 or higher, 9.0P4 or higher, or 9.1P5 or higher of NetApp Clustered Data ONTAP.
3
What systems are affected by CVE-2017-7947?
CVE-2017-7947 affects NetApp Clustered Data ONTAP versions 8.3.2 before P11, 9.0 before P4, and 9.1 before P5.
4
What kind of information can be exposed by CVE-2017-7947?
CVE-2017-7947 can expose sensitive password information that is logged non-interactively on the command line.
5
Is CVE-2017-7947 a remote or local attack vector?
CVE-2017-7947 typically requires local access to the command line interface to exploit the vulnerability.