CVE-2024-21982
Netapp Clustered Data Ontap 9.4 – 9.8
CVSS Score v3.1
4.8
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS Score
0.0037
30th percentile
Summary
CVE-2024-21982 is a medium-severity an unspecified weakness vulnerability in Netapp Clustered Data Ontap. Its CVSS base score is 4.8 (Medium).
Operationally, ranked at the 30th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-19588
Vulnerability Data
ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2023-27314Same product: Netapp Clustered Data Ontap
CVE-2024-21985Same product: Netapp Clustered Data Ontap
CVE-2024-38474Same product: Netapp Clustered Data Ontap
CVE-2024-38477Same product: Netapp Clustered Data Ontap
CVE-2023-3107Same product: Netapp Clustered Data Ontap
CVE-2024-38476Same product: Netapp Clustered Data Ontap
CVE-2024-21993Same product class: NAS / storage appliance
CVE-2025-26517Same product class: NAS / storage appliance
CVE-2025-26515Same product class: NAS / storage appliance
CVE-2023-27318Same product class: NAS / storage appliance
Affected Assets
netapp
clustered data ontap
9.10.1, 9.11.1, 9.12.1, 9.13.1, 9.8 · 9.4 — 9.8
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.