CVE-2024-21987: Improper Authorization Vulnerability in SnapCenter
SnapCenter versions 4.8 prior to 5.0 are susceptible to a vulnerability which could allow an authenticated SnapCenter Server user to modify system logging configuration settings
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SnapCenterto a version that resolves this vulnerability.Fixed in 5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21987?
CVE-2024-21987 has been classified with a medium severity rating as it impacts authenticated users altering system logging settings.
How do I fix CVE-2024-21987?
To fix CVE-2024-21987, upgrade your SnapCenter server to version 5.0 or later.
Who is affected by CVE-2024-21987?
CVE-2024-21987 affects all users of SnapCenter versions 4.8 up to but not including 5.0.
What is the impact of CVE-2024-21987?
The impact of CVE-2024-21987 allows an authenticated user to modify important system logging configuration settings.
Is there a workaround for CVE-2024-21987?
There are no known workarounds for CVE-2024-21987; upgrading to the latest version is the recommended action.