First published: Wed Apr 17 2024(Updated: )
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
NetApp ONTAP Select Deploy | >=9.12.1.0<9.15.0.0 | |
NetApp ONTAP Select Deploy | >=9.12.1<=9.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21990 is considered a critical vulnerability due to the presence of hard-coded credentials that can lead to security breaches.
To fix CVE-2024-21990, upgrade to a version of NetApp ONTAP Select Deploy administration utility that is higher than 9.15.0.0.
The vulnerability could allow an attacker to view and modify Deploy configuration and gain unauthorized access to system accounts.
CVE-2024-21990 affects NetApp ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x, and 9.14.1.x.
The vendor responsible for CVE-2024-21990 is NetApp.