CVE-2024-21993: Information Disclosure Vulnerability in SnapCenter
Published Jul 9, 2024
·Updated
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.
Affected Software
2 affected components
NetApp Snapcenter<5.0
NetApp Snapcenter=5.0
Event History
Jul 9, 2024
CVE Published
via MITRE·09:26 PM
Data Sourced
via MITRE·09:26 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-21993?
CVE-2024-21993 has a medium severity rating, indicating potential risks related to credential exposure.
2
How do I fix CVE-2024-21993?
To address CVE-2024-21993, upgrade NetApp SnapCenter to version 5.0p1 or later.
3
What systems are affected by CVE-2024-21993?
CVE-2024-21993 affects all versions of NetApp SnapCenter prior to 5.0p1.
4
What type of attack does CVE-2024-21993 allow?
CVE-2024-21993 allows an authenticated attacker to discover plaintext credentials.
5
Is it safe to use versions of SnapCenter prior to 5.0p1 due to CVE-2024-21993?
Using versions of SnapCenter prior to 5.0p1 poses a security risk due to the vulnerability outlined in CVE-2024-21993.