| Vulnerability Name: | CVE-2018-5490 (CCN-147953) | ||||||||||||
| Assigned: | 2017-02-07 | ||||||||||||
| Published: | 2017-02-07 | ||||||||||||
| Updated: | 2019-10-03 | ||||||||||||
| Summary: | Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are requested to update their systems to the NetApp Data ONTAP 8.3 GA release. | ||||||||||||
| CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
4.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-732 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2018-5490 Source: XF Type: UNKNOWN netapp-cve20185490-sec-bypass(147953) Source: CCN Type: NetApp Advisory Number NTAP-20150324-0001 Improper Handling of Export Policy Rules for SMBv2 and SMBv3 Clients Vulnerability in Clustered Data ONTAP 8.3 Release Candidates Source: CONFIRM Type: Vendor Advisory https://security.netapp.com/advisory/ntap-20150324-0001/ | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||