7.6

CVE-2024-21985

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 
and 9.13.1P4 are susceptible to a vulnerability which could allow an 
authenticated user with multiple remote accounts with differing roles to
 perform actions via REST API beyond their intended privilege. Possible 
actions include viewing limited configuration details and metrics or 
modifying limited settings, some of which could result in a Denial of 
Service (DoS).



Data is provided by the National Vulnerability Database (NVD)
NetappClustered Data Ontap Version >= 9.0 < 9.9.1
NetappClustered Data Ontap Version >= 9.10.0 < 9.10.1
NetappClustered Data Ontap Version >= 9.11.0 < 9.11.1
NetappClustered Data Ontap Version >= 9.12.0 < 9.12.1
NetappClustered Data Ontap Version >= 9.13.0 < 9.13.1
NetappClustered Data Ontap Version9.9.1 Update-
NetappClustered Data Ontap Version9.10.1 Update-
NetappClustered Data Ontap Version9.11.1 Update-
NetappClustered Data Ontap Version9.12.1 Update-
NetappClustered Data Ontap Version9.13.1 Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.17% 0.385
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
security-alert@netapp.com 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.