Cyber Resilience

CVE-2024-21982

Netapp Clustered Data Ontap 9.4 – 9.8

Published
12 January 2024
Modified
17 June 2026
Patch / advisory
CVSS Score v3.1 4.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
EPSS Score 0.0037 30th percentile
Risk Priority 38 floored blend · peak EPSS

Summary

CVE-2024-21982 is a medium-severity an unspecified weakness vulnerability in Netapp Clustered Data Ontap. Its CVSS base score is 4.8 (Medium).

Operationally, ranked at the 30th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-27314Same product: Netapp Clustered Data Ontap
CVE-2024-21985Same product: Netapp Clustered Data Ontap
CVE-2024-38474Same product: Netapp Clustered Data Ontap
CVE-2024-38477Same product: Netapp Clustered Data Ontap
CVE-2023-3107Same product: Netapp Clustered Data Ontap
CVE-2024-38476Same product: Netapp Clustered Data Ontap
CVE-2024-21993Same product class: NAS / storage appliance
CVE-2025-26517Same product class: NAS / storage appliance
CVE-2025-26515Same product class: NAS / storage appliance
CVE-2023-27318Same product class: NAS / storage appliance

Affected Assets

netapp
clustered data ontap
9.10.1, 9.11.1, 9.12.1, 9.13.1, 9.8 · 9.4 — 9.8

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References