CVE-2019-5504: Critical severity netapp ontap select deploy vulnerability
Published Sep 24, 2019
·Updated
ONTAP Select Deploy administration utility versions 2.12 & 2.12.1 ship with an HTTP service bound to the network allowing unauthenticated remote attackers to perform administrative actions.
Affected Software
2 affected components
NetApp ONTAP Select Deploy administration utility=2.12
NetApp ONTAP Select Deploy administration utility=2.12.1
Remediation
Patch Available
Event History
Sep 24, 2019
CVE Published
via MITRE·07:53 PM
Data Sourced
via MITRE·07:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5504?
CVE-2019-5504 is considered a critical vulnerability due to the potential for unauthenticated remote administrative access.
2
How do I fix CVE-2019-5504?
To mitigate CVE-2019-5504, it is recommended to disable the HTTP service or upgrade to a fixed version of the software.
3
What versions of software are affected by CVE-2019-5504?
CVE-2019-5504 affects NetApp ONTAP Select Deploy administration utility versions 2.12 and 2.12.1.
4
Can CVE-2019-5504 be exploited remotely?
Yes, CVE-2019-5504 can be exploited remotely by unauthenticated attackers due to the exposed HTTP service.
5
What are the potential impacts of CVE-2019-5504?
Exploitation of CVE-2019-5504 can lead to unauthorized administrative actions on the affected systems.