CVE-2022-23236: Medium severity netapp e-series santricity os controller vulnerability
Published Jun 1, 2022
·Updated
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.
Affected Software
1 affected component
NetApp E-Series SANtricity OS Controller>=11.40<=11.70.2
Event History
Jun 1, 2022
CVE Published
via MITRE·01:46 PM
Data Sourced
via MITRE·01:46 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2022-23236.
2
What is the title of this vulnerability?
The title of this vulnerability is 'E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.'
3
What is the severity level of CVE-2022-23236?
The severity level of CVE-2022-23236 is medium with a CVSS score of 4.4.
4
How does CVE-2022-23236 affect NetApp E-Series SANtricity OS Controller?
CVE-2022-23236 affects NetApp E-Series SANtricity OS Controller versions 11.40 through 11.70.2.
5
Is there a fix available for CVE-2022-23236?
Yes, NetApp has released a fix for CVE-2022-23236. Please refer to the advisory linked in the references for more information.