CVE-2019-5506: Medium severity ibm data ontap vulnerability
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-5506?
CVE-2019-5506 is a vulnerability in Clustered Data ONTAP versions 9.0 and higher that allows for impersonation via man-in-the-middle attacks.
How severe is CVE-2019-5506?
The severity of CVE-2019-5506 is medium, with a CVSSv3 score of 5.9.
Which versions of Clustered Data ONTAP are affected by CVE-2019-5506?
Clustered Data ONTAP versions 9.0 to 9.6-p3 are affected by CVE-2019-5506.
What is the vulnerability description of CVE-2019-5506?
Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances, making them susceptible to impersonation via man-in-the-middle attacks.
How can I fix CVE-2019-5506?
To fix CVE-2019-5506, it is recommended to upgrade Clustered Data ONTAP to a version higher than 9.6-p3 that enforces hostname verification.