CVE-2024-21990

ONTAP Select Deploy administration utility versions 9.12.1.x, 9.13.1.x and 9.14.1.x contain hard-coded credentials that could allow an attacker to view Deploy configuration information and modify the account credentials.
Configurations

Configuration 1 (hide)

cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:*:*:*:*:*:*:*:*

History

10 Feb 2025, 19:29

Type Values Removed Values Added
CWE CWE-798
CPE cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:*:*:*:*:*:*:*:*
First Time Netapp
Netapp ontap Select Deploy Administration Utility
References () https://security.netapp.com/advisory/ntap-20240411-0002/ - () https://security.netapp.com/advisory/ntap-20240411-0002/ - Vendor Advisory

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20240411-0002/ - () https://security.netapp.com/advisory/ntap-20240411-0002/ -

18 Apr 2024, 13:04

Type Values Removed Values Added
Summary
  • (es) Las versiones 9.12.1.x, 9.13.1.x y 9.14.1.x de la utilidad de administración ONTAP Select Deploy contienen credenciales codificadas que podrían permitir a un atacante ver la información de configuración de Deploy y modificar las credenciales de la cuenta.

17 Apr 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-17 20:15

Updated : 2025-02-10 19:29


NVD link : CVE-2024-21990

Mitre link : CVE-2024-21990

CVE.ORG link : CVE-2024-21990


JSON object : View

Products Affected

netapp

  • ontap_select_deploy_administration_utility
CWE
CWE-259

Use of Hard-coded Password

CWE-798

Use of Hard-coded Credentials