CVE-2016-1895
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
NetApp Data ONTAP before 8.2.5 and 8.3.x before 8.3.2P12 allow remote authenticated users to cause a denial of service via vectors related to unsafe user input string handling.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cve@mitre.org — https://kb.netapp.com/support/s/article/NTAP-20170831-0003
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| netapp | data_ontap | {"endIncluding":"8.2.4"} | |
| netapp | data_ontap | 8.3.2p12 | |
| netapp | data_ontap | 9.0 | |
References
CWEs
CWE-134
Verify integrity in audit chain (admin only). AS-IS.