CVE-2016-1563
medium
CVSS v3
6.8
CVSS v2
5.8
VIR risk
6.8
Description
NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Predictions
Exploit likelihood
77%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://kb.netapp.com/support/index?page=content&id=9010064
References
CWEs
CWE-20 CWE-200
Verify integrity in audit chain (admin only). AS-IS.