Home / Security / Advisories / NTAP-20171208-0002

NTAP-20171208-0002 — CVE-2016-6904 Plain Text Authentication vulnerability in VASA Provider for Clustered Data ONTAP

Published 2017-12-08 · Updated 2017-12-08 · Status: Final · Exploitation: Public

Official advisory: NTAP-20171208-0002 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

CVEs in this advisory

Affected products

What to do

  1. Check your ONTAP versions against the official advisory's affected-versions table.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).

Related reading

Browse all ONTAP CVEs → · Security hub