5.3
CVE-2024-21988
- EPSS 0.06%
- Veröffentlicht 14.06.2024 22:15:10
- Zuletzt bearbeitet 13.12.2024 17:26:35
- Quelle security-alert@netapp.com
- CVE-Watchlists
- Unerledigt
CVE-2024-21988 SSH Cryptographic Implementation Vulnerability in StorageGRID (formerly StorageGRID Webscale)
StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ Storagegrid Version < 11.7.0.9
Netapp ≫ Storagegrid Version >= 11.8.0 < 11.8.0.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.188 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| security-alert@netapp.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.