« Volver al listado

CVE-2021-27004

Estado: ModificadaMedia (5.5)—

System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27004",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.7,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.1,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-alert@netapp.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "System Manager 9.x",
          "versions": [
            {
              "status": "affected",
              "version": "System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-11-01T13:15:07.767",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/NTAP-20211029-0001/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-alert@netapp.com"
    },
    {
      "url": "https://security.netapp.com/advisory/NTAP-20211029-0001/",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which could allow a local attacker to discover plaintext iSCSI CHAP credentials."
    },
    {
      "lang": "es",
      "value": "System Manager versiones 9.x versiones 9.7 y superiores, anteriores a 9.7P16, 9.8P7 y 9.9.1P2, son susceptibles de una vulnerabilidad que podría permitir a un atacante local descubrir credenciales iSCSI CHAP en texto plano"
    }
  ],
  "lastModified": "2026-06-17T03:44:07.630",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:ontap_system_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9691B34C-67DE-44CA-8494-088DE34CBDDD",
              "versionEndExcluding": "9.7",
              "versionStartIncluding": "9.0"
            },
            {
              "criteria": "cpe:2.3:a:netapp:ontap_system_manager:9.7:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A28FA31-118B-4867-9BDB-32C3C0BF3007"
            },
            {
              "criteria": "cpe:2.3:a:netapp:ontap_system_manager:9.8:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8F1AEED-0DFD-43F1-A422-919C04503629"
            },
            {
              "criteria": "cpe:2.3:a:netapp:ontap_system_manager:9.9.12:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14E92ED7-0B54-474B-9F8E-4393791017C1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-alert@netapp.com"
}