CVE-2019-5505: Critical severity netapp ontap select deploy vulnerability
Published Sep 24, 2019
·Updated
ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext.
Affected Software
2 affected components
NetApp ONTAP Select Deploy administration utility>=2.2<=2.12.1
NetApp ONTAP Select Deploy administration utility
Remediation
Patch Available
Event History
Sep 24, 2019
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-5505?
CVE-2019-5505 has a medium severity rating due to the transmission of credentials in plaintext.
2
How do I fix CVE-2019-5505?
To resolve CVE-2019-5505, upgrade to a version of the ONTAP Select Deploy administration utility that is higher than 2.12.1.
3
What impact does CVE-2019-5505 have on my system?
CVE-2019-5505 allows attackers to intercept and access sensitive credentials being transmitted in plaintext.
4
Which versions are affected by CVE-2019-5505?
CVE-2019-5505 affects ONTAP Select Deploy administration utility versions 2.2 through 2.12.1.
5
Is there a workaround for CVE-2019-5505?
A workaround for CVE-2019-5505 is to limit network access to the administration utility to trusted users until an upgrade can be performed.