CVE-2018-5490
Last modified
CVE-2018-5490 is a vulnerability of currently unknown severity. Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the NetApp Data ONTAP 8.3 GA release.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Clustered Data Ontap | < 8.3 |
References
- https://security.netapp.com/advisory/ntap-20150324-0001/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20150324-0001/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5490?
How severe is CVE-2018-5490?
How do I fix CVE-2018-5490?
Are you affected by CVE-2018-5490?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
