First published: Wed Oct 09 2019(Updated: )
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp Clustered Data ONTAP | >=9.0<=9.6 | |
NetApp Clustered Data ONTAP | =9.6-p1 | |
NetApp Clustered Data ONTAP | =9.6-p2 | |
NetApp Clustered Data ONTAP | =9.6-p3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5506 is a vulnerability in Clustered Data ONTAP versions 9.0 and higher that allows for impersonation via man-in-the-middle attacks.
The severity of CVE-2019-5506 is medium, with a CVSSv3 score of 5.9.
Clustered Data ONTAP versions 9.0 to 9.6-p3 are affected by CVE-2019-5506.
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances, making them susceptible to impersonation via man-in-the-middle attacks.
To fix CVE-2019-5506, it is recommended to upgrade Clustered Data ONTAP to a version higher than 9.6-p3 that enforces hostname verification.