CVE-2024-21990: Default Privileged Account Credentials Vulnerability in ONTAP Select Deploy administration utility
ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21990?
CVE-2024-21990 is considered a critical vulnerability due to the presence of hard-coded credentials that can lead to security breaches.
How do I fix CVE-2024-21990?
To fix CVE-2024-21990, upgrade to a version of NetApp ONTAP Select Deploy administration utility that is higher than 9.15.0.0.
What are the potential consequences of CVE-2024-21990?
The vulnerability could allow an attacker to view and modify Deploy configuration and gain unauthorized access to system accounts.
Which versions are affected by CVE-2024-21990?
CVE-2024-21990 affects NetApp ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x, and 9.14.1.x.
Who is the vendor responsible for CVE-2024-21990?
The vendor responsible for CVE-2024-21990 is NetApp.