Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-21985
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Privilege Escalation Vulnerability in ONTAP 9
Source: NVD (National Vulnerability Database)
Vulnerability Description
ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 and 9.13.1P4 are susceptible to a vulnerability which could allow an authenticated user with multiple remote accounts with differing roles to perform actions via REST API beyond their intended privilege. Possible actions include viewing limited configuration details and metrics or modifying limited settings, some of which could result in a Denial of Service (DoS).
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
特权管理不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
NetApp ONTAP 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NetApp ONTAP是美国网络器械(NetApp)公司的一款专有操作系统。用于存储磁盘阵列。 NetApp ONTAP 9.9.1P18、9.10.1P16、9.11.1P13、9.12.1P10 和 9.13.1P4 之前版本存在安全漏洞,该漏洞源于允许拥有多个具有不同角色的远程帐户的经过身份验证的用户通过 REST API 执行超出其权限的操作,包括查看有限的配置详细信息和指标或修改有限的设置,其中一些可能会导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
NetAppONTAP 9 9.0 ~ 9.9.1P18 -
II. Public POCs for CVE-2024-21985
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-21985
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-21985

No comments yet


Leave a comment