Vulnerability Description
Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identity.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Network Appliance | Data Ontap | <= 7.0 |
References
- http://marc.info/?l=bugtraq&m=113028385702680&w=2
- http://secunia.com/advisories/17321Patch
- http://securitytracker.com/id?1015103
- http://www.matasano.com/advisories/netapp-iSCSI.txt
- http://www.securityfocus.com/bid/15197
- http://www.vupen.com/english/advisories/2005/2193
- http://marc.info/?l=bugtraq&m=113028385702680&w=2
- http://secunia.com/advisories/17321Patch
- http://securitytracker.com/id?1015103
- http://www.matasano.com/advisories/netapp-iSCSI.txt
- http://www.securityfocus.com/bid/15197
- http://www.vupen.com/english/advisories/2005/2193
FAQ
What is CVE-2005-3327?
CVE-2005-3327 is a vulnerability with a CVSS score of 7.5 (HIGH). Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation pro...
How severe is CVE-2005-3327?
CVE-2005-3327 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-3327?
Check the references section above for vendor advisories and patch information. Affected products include: Network Appliance Data Ontap.