CVE-2021-26995: High severity netapp e-series santricity os controller vulnerability
Published Jun 11, 2021
·Updated
E-Series SANtricity OS Controller Software 11.x versions prior to 11.70.1 are susceptible to a vulnerability which when successfully exploited could allow privileged attackers to execute arbitrary code.
Affected Software
1 affected component
NetApp E-Series SANtricity OS Controller>=11.0.0<11.70.1
Event History
Jun 11, 2021
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-26995?
CVE-2021-26995 is classified as a critical vulnerability due to its potential for arbitrary code execution by privileged attackers.
2
How do I fix CVE-2021-26995?
To mitigate CVE-2021-26995, upgrade the E-Series SANtricity OS Controller software to version 11.70.1 or later.
3
Which versions are affected by CVE-2021-26995?
CVE-2021-26995 affects E-Series SANtricity OS Controller versions 11.0.0 to 11.70.0.
4
What types of attacks can exploit CVE-2021-26995?
CVE-2021-26995 can be exploited by privileged attackers to execute arbitrary code on the affected systems.
5
Is there a workaround for CVE-2021-26995?
There are no known workarounds for CVE-2021-26995; the only solution is to upgrade to the patched version.