First published: Wed Apr 17 2024(Updated: )
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x are susceptible to a vulnerability which when successfully exploited could allow a read-only user to escalate their privileges.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp ONTAP Select Deploy Utility | >=9.12.1<=9.14.1 | |
NetApp ONTAP Select Deploy | >=9.12.1<=9.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21989 has a high severity rating due to its potential to allow privilege escalation for read-only users.
To fix CVE-2024-21989, it is recommended to upgrade to a version of ONTAP Select Deploy that is not affected, specifically any version beyond 9.14.1.
CVE-2024-21989 affects ONTAP Select Deploy versions 9.12.1.x, 9.13.1.x, and 9.14.1.x.
The impact of CVE-2024-21989 allows unauthorized escalation of privileges for users who only have read-only access.
There are no known workarounds for CVE-2024-21989, so upgrading to a secure version is essential.