First published: Fri Jun 14 2024(Updated: )
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp StorageGRID Webscale | <11.7.0.9 | |
NetApp StorageGRID Webscale | >=11.8.0<11.8.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21988 is considered a high severity vulnerability due to the potential for sensitive information disclosure via MitM attacks.
To fix CVE-2024-21988, upgrade your StorageGRID version to 11.7.0.9 or 11.8.0.5 or later.
CVE-2024-21988 affects StorageGRID versions prior to 11.7.0.9 and versions from 11.8.0.0 up to but not including 11.8.0.5.
CVE-2024-21988 facilitates complex Man-in-the-Middle (MitM) attacks that can lead to the disclosure of sensitive information.
There are no documented workarounds for CVE-2024-21988; updating to a fixed version is the recommended approach.