First published: Mon Nov 01 2021(Updated: )
Clustered Data ONTAP versions 9.6 and higher prior to 9.6P16, 9.7P16, 9.8P7 and 9.9.1P3 are susceptible to a vulnerability which could allow a remote attacker to cause a crash of the httpd server.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp OnCommand System Manager | >=9.0<9.7 | |
NetApp OnCommand System Manager | =9.7 | |
NetApp OnCommand System Manager | =9.8 | |
NetApp OnCommand System Manager | =9.9.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27005 is classified as a medium severity vulnerability.
CVE-2021-27005 allows a remote attacker to crash the httpd server in affected versions of NetApp OnCommand System Manager.
To mitigate CVE-2021-27005, upgrade your NetApp OnCommand System Manager to a version that is patched, such as 9.6P16, 9.7P16, 9.8P7, or 9.9.1P3.
CVE-2021-27005 affects Clustered Data ONTAP versions 9.6 and higher, specifically those prior to 9.6P16, 9.7P16, 9.8P7, and 9.9.1P3.
Yes, CVE-2021-27005 can be exploited remotely by an attacker to crash the httpd server.