---
cve: "CVE-2024-21985"
severity: "HIGH"
cvss: 7.6
epss: "33%"
vendor: "NetApp"
kev: false
exploited: false
published: "2024-01-26 16:15:22"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T01:57:14+02:00"
---

# CVE-2024-21985

> 7.6 HIGH

## Beschreibung

ONTAP 9 versions prior to 9.9.1P18, 9.10.1P16, 9.11.1P13, 9.12.1P10 
and 9.13.1P4 are susceptible to a vulnerability which could allow an 
authenticated user with multiple remote accounts with differing roles to
 perform actions via REST API beyond their intended privilege. Possible 
actions include viewing limited configuration details and metrics or 
modifying limited settings, some of which could result in a Denial of 
Service (DoS).

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Gering | warn |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://security.netapp.com/advisory/ntap-20240126-0001/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-21985) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
