Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Snap Creator Framework | <= 4.3.0 |
Related Weaknesses (CWE)
References
- https://kb.netapp.com/support/s/article/cve-2016-5372-cross-site-request-forgeryVendor Advisory
- https://security.netapp.com/advisory/ntap-20160622-0001/
- https://kb.netapp.com/support/s/article/cve-2016-5372-cross-site-request-forgeryVendor Advisory
- https://security.netapp.com/advisory/ntap-20160622-0001/
FAQ
What is CVE-2016-5372?
CVE-2016-5372 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in NetApp Snap Creator Framework before 4.3.0P1 allows remote attackers to hijack the authentication of users for requests that have unspecified impact ...
How severe is CVE-2016-5372?
CVE-2016-5372 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5372?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Snap Creator Framework.