Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27317

Опубликовано: 15 дек. 2023
Источник: nvd
CVSS3: 4.3
CVSS3: 4.6
EPSS Низкий

Описание

ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked after a system reboot or power cycle or a single SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This could lead to disclosure of sensitive information to an attacker with physical access to the unlocked drives.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:netapp:ontap:9.12.1:p8:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.13.1:p4:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap:9.13.1:p5:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00337
Низкий

4.3 Medium

CVSS3

4.6 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4.3
github
около 2 лет назад

ONTAP 9 versions 9.12.1P8, 9.13.1P4, and 9.13.1P5 are susceptible to a vulnerability which will cause all SAS-attached FIPS 140-2 drives to become unlocked after a system reboot or power cycle or a single SAS-attached FIPS 140-2 drive to become unlocked after reinsertion. This could lead to disclosure of sensitive information to an attacker with physical access to the unlocked drives.

EPSS

Процентиль: 56%
0.00337
Низкий

4.3 Medium

CVSS3

4.6 Medium

CVSS3

Дефекты

CWE-200
NVD-CWE-noinfo