VulnerabilityModified
CVE-2017-12422
NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.
MEDIUM 6.5EPSS 1.63%
Does this matter?
Lower severity and a low EPSS score (1.63%). Track it; it rarely justifies an emergency change on its own.
Description
NetApp StorageGRID Webscale 10.2.x before 10.2.2.3, 10.3.x before 10.3.0.4, and 10.4.x before 10.4.0.2 allow remote authenticated users to delete arbitrary objects via unspecified vectors.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.63% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- netapp/storagegrid webscale
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/100535Third Party Advisory, VDB Entry
- https://kb.netapp.com/support/s/article/NTAP-20170825-0001Vendor Advisory
- http://www.securityfocus.com/bid/100535Third Party Advisory, VDB Entry
- https://kb.netapp.com/support/s/article/NTAP-20170825-0001Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.