Vulnerability Description
E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | E-Series Santricity Os Controller | >= 11.40, <= 11.70.2 |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/NTAP-20220527-0001/Vendor Advisory
- https://security.netapp.com/advisory/NTAP-20220527-0001/Vendor Advisory
FAQ
What is CVE-2022-23236?
CVE-2022-23236 is a vulnerability with a CVSS score of 4.4 (MEDIUM). E-Series SANtricity OS Controller Software versions 11.40 through 11.70.2 store the LDAP BIND password in plaintext within a file accessible only to privileged users.
How severe is CVE-2022-23236?
CVE-2022-23236 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-23236?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp E-Series Santricity Os Controller.