CVE-2019-5492: High severity netapp hyper converged infrastructure vulnerability
Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-5492.
What is the severity level of CVE-2019-5492?
The severity level of CVE-2019-5492 is high with a score of 7.5.
Which software versions are affected by CVE-2019-5492?
CVE-2019-5492 affects NetApp HCI Compute Node versions prior to 1.4P2 and Element Plug-in for vCenter Server versions prior to 4.2.3.
How can an unauthenticated attacker exploit CVE-2019-5492?
An unauthenticated attacker can exploit CVE-2019-5492 by gaining access to sensitive account information through the Element Plug-in for vCenter Server.
Where can I find more information about CVE-2019-5492?
More information about CVE-2019-5492 can be found at http://www.securityfocus.com/bid/108105 and https://security.netapp.com/advisory/ntap-20190426-0001/