4.6

CVE-2023-27317

ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a 
vulnerability which will cause all SAS-attached FIPS 140-2 drives to 
become unlocked after a system reboot or power cycle or a single 
SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This
 could lead to disclosure of sensitive information to an attacker with 
physical access to the unlocked drives. 

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NetappOntap Version9.12.1 Updatep8
NetappOntap Version9.13.1 Updatep4
NetappOntap Version9.13.1 Updatep5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.558
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.6 0.9 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
security-alert@netapp.com 4.3 0.7 3.6
CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.