CVE-2018-5492: Input Validation
Published Oct 4, 2018
·Updated
NetApp E-Series SANtricity OS Controller Software 11.30 and later version 11.30.5 is susceptible to unauthenticated remote code execution.
Affected Software
1 affected component
NetApp E-Series SANtricity OS Controller>=11.0<=11.40
Event History
Oct 4, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-5492?
CVE-2018-5492 has a critical severity rating due to its potential for unauthenticated remote code execution.
2
How do I fix CVE-2018-5492?
To remediate CVE-2018-5492, upgrade to NetApp E-Series SANtricity OS Controller version 11.30.5 or later.
3
What versions of NetApp E-Series SANtricity OS Controller are affected by CVE-2018-5492?
CVE-2018-5492 affects NetApp E-Series SANtricity OS Controller versions from 11.0 to 11.30.4.
4
Can CVE-2018-5492 be exploited without authentication?
Yes, CVE-2018-5492 can be exploited without authentication, leading to remote code execution.
5
Who is the vendor for the affected software in CVE-2018-5492?
The vendor for the affected software in CVE-2018-5492 is NetApp.