CVE-2019-5502: Weak Encryption
Published Aug 5, 2019
·Updated
SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.
Affected Software
3 affected components
NetApp Data ONTAP<8.2.5
NetApp Data ONTAP=8.2.5-p1
NetApp Data ONTAP=8.2.5-p2
Event History
Aug 5, 2019
CVE Published
via MITRE·06:48 PM
Data Sourced
via MITRE·06:48 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2019-5502?
CVE-2019-5502 is a vulnerability in SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 that has weak cryptography.
2
What is the severity of CVE-2019-5502?
The severity of CVE-2019-5502 is critical with a CVSS score of 9.1.
3
How can CVE-2019-5502 be exploited?
CVE-2019-5502 can be exploited to lead to information disclosure or addition or modification of data.
4
Which versions of Data ONTAP are affected by CVE-2019-5502?
Versions prior to 8.2.5P3 of Data ONTAP operating in 7-Mode are affected by CVE-2019-5502.
5
How can I fix CVE-2019-5502?
To fix CVE-2019-5502, update Data ONTAP to version 8.2.5P3 or higher.