Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-5490

Опубликовано: 03 авг. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the NetApp Data ONTAP 8.3 GA release.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:netapp:clustered_data_ontap:*:*:*:*:*:*:*:*
Версия до 8.3 (исключая)

EPSS

Процентиль: 55%
0.0032
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the NetApp Data ONTAP 8.3 GA release.

EPSS

Процентиль: 55%
0.0032
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-732