VulnerabilityModified
CVE-2020-8585
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
MEDIUM 5.5EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
OnCommand Unified Manager Core Package versions prior to 5.2.5 may disclose sensitive account information to unauthorized users via the use of PuTTY Link (plink).
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- netapp/oncommand unified manager
- Source
- security-alert@netapp.com
References
- https://security.netapp.com/advisory/NTAP-20210128-0001Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Vendor Advisory
- https://security.netapp.com/advisory/NTAP-20210128-0001Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210128-0001/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.