CVE-2020-8585
MEDIUMCVSS 5.5/10EPSS 0.41%
Last modified
CVE-2020-8585 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Oncommand Unified Manager | < 5.2.5 |
References
- https://security.netapp.com/advisory/NTAP-20210128-0001Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Vendor Advisory
- https://security.netapp.com/advisory/NTAP-20210128-0001Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8585?
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
How severe is CVE-2020-8585?
CVE-2020-8585 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8585?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8579Clustered Data ONTAP versions 9.7 through 9.7P7 are suscepti…7.5
- CVE-2020-8580SANtricity OS Controller Software versions 11.30 and higher …7.5
- CVE-2020-8581Clustered Data ONTAP versions prior to 9.3P20 and 9.5 are su…6.5
- CVE-2020-8582Element Software versions prior to 12.2 and HCI versions pri…6.5
- CVE-2020-8583Element Software versions prior to 12.2 and HCI versions pri…7.5
- CVE-2020-8584Element OS versions prior to 1.8P1 and 12.2 are susceptible …9.8
- CVE-2020-8586Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-8587OnCommand System Manager 9.x versions prior to 9.3P20 and 9.…5.5
- CVE-2020-8588Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are…3.5
- CVE-2020-8589Clustered Data ONTAP versions prior to 9.3P20 and 9.5P15 are…3.5
- CVE-2020-8590Clustered Data ONTAP versions prior to 9.1P18 and 9.3P12 are…3.3
- CVE-2020-8591eG Manager 7.1.2 allows authentication bypass via a com.egur…9.8
Are you affected by CVE-2020-8585?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
