CVE-2020-8590: Low severity ibm data ontap vulnerability
Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are susceptible to a vulnerability which could allow an attacker to discover node names via AutoSupport bundles even when the –remove-private-data parameter is set to true.
Affected Software
Event History
Frequently Asked Questions
What versions of NetApp Clustered Data ONTAP are affected by CVE-2020-8590?
CVE-2020-8590 affects Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12.
What is the nature of the vulnerability described in CVE-2020-8590?
The vulnerability allows an attacker to discover node names via AutoSupport bundles even with the –remove-private-data parameter set to true.
Is there a known fix for CVE-2020-8590?
Yes, upgrading to Clustered Data ONTAP versions 9.1P18 or 9.3P12 or later mitigates CVE-2020-8590.
How can I verify if my NetApp Clustered Data ONTAP is vulnerable to CVE-2020-8590?
You can check your current version of NetApp Clustered Data ONTAP against the affected versions listed in CVE-2020-8590.
What potential impact does CVE-2020-8590 pose to my network security?
CVE-2020-8590 may expose sensitive node name information to unauthorized users, which can be used for further attacks.