CVE-2020-8578: Low severity ibm data ontap vulnerability
Published Feb 8, 2021
·Updated
Clustered Data ONTAP versions prior to 9.3P20 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
Affected Software
13 affected components
NetApp Clustered Data ONTAP<9.3
NetApp Clustered Data ONTAP=9.3
NetApp Clustered Data ONTAP=9.3-p1
NetApp Clustered Data ONTAP=9.3-p10
NetApp Clustered Data ONTAP=9.3-p2
NetApp Clustered Data ONTAP=9.3-p3
NetApp Clustered Data ONTAP=9.3-p4
NetApp Clustered Data ONTAP=9.3-p5
NetApp Clustered Data ONTAP=9.3-p6
NetApp Clustered Data ONTAP=9.3-p7
NetApp Clustered Data ONTAP=9.3-p8
NetApp Clustered Data ONTAP=9.3-p9
NetApp Clustered Data ONTAP=9.3-rc1
Event History
Feb 8, 2021
CVE Published
via MITRE·09:38 PM
Data Sourced
via MITRE·09:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8578?
CVE-2020-8578 is classified as a medium severity vulnerability.
2
How do I fix CVE-2020-8578?
To fix CVE-2020-8578, upgrade to Clustered Data ONTAP version 9.3P20 or later.
3
Which versions of NetApp Clustered Data ONTAP are affected by CVE-2020-8578?
CVE-2020-8578 affects Clustered Data ONTAP versions prior to 9.3P20.
4
What type of information can be exposed due to CVE-2020-8578?
CVE-2020-8578 may allow attackers to discover node names through AutoSupport bundles.
5
Is the –remove-private-data parameter effective against CVE-2020-8578?
No, the –remove-private-data parameter does not prevent the exposure of node names in this vulnerability.