Vulnerabilities > Netapp > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-07 CVE-2015-7691 Improper Input Validation vulnerability in NTP
The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations.
network
low complexity
ntp oracle debian netapp redhat CWE-20
5.0
2017-08-07 CVE-2015-7887 Improper Access Control vulnerability in Netapp Snapcenter Server 1.0
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.
network
low complexity
netapp CWE-284
6.5
2017-07-25 CVE-2017-8919 Unspecified vulnerability in Netapp Oncommand API Services 1.0/1.1/1.2
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.
network
low complexity
netapp
4.0
2017-07-24 CVE-2015-7703 Improper Input Validation vulnerability in NTP
The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to arbitrary files via the :config command.
4.3
2017-07-17 CVE-2017-7947 Information Exposure vulnerability in Netapp Clustered Data Ontap 8.3.2/9.0/9.1
NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line.
network
low complexity
netapp CWE-200
5.0
2017-07-03 CVE-2016-5045 Information Exposure vulnerability in Netapp Oncommand System Manager 8.3/8.3.1/8.3.2
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup.
network
netapp CWE-200
6.8
2017-07-03 CVE-2016-3998 Permissions, Privileges, and Access Controls vulnerability in Netapp Altavault
NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
network
high complexity
netapp CWE-264
5.1
2017-07-03 CVE-2016-3997 7PK - Security Features vulnerability in Netapp Clustered Data Ontap 8.3.1
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.
network
netapp CWE-254
6.8
2017-07-03 CVE-2016-3400 7PK - Security Features vulnerability in Netapp Data Ontap 8.1/8.2
NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol.
network
netapp CWE-254
6.8
2017-05-26 CVE-2017-7439 Information Exposure vulnerability in Netapp Oncommand Unified Manager Core Package
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.
network
low complexity
netapp CWE-200
5.0