Oncommand Unified Manager For Clustered Data Ontap
Vendor:
First CVE: Nov 10, 2016 · Active for 9 years
4
Total CVEs
More Total CVEs than 75% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
25.0%
KEV Rate
Higher KEV Rate than 99% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Oncommand Unified Manager For Clustered Data Ontap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2016
9 years ago
Most Recent CVE
Sep 1, 2017
3,252 days ago
CVE Severity & Scoring
Oncommand Unified Manager For Clustered Data Ontap4 CVEs
25%
50%
25%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High1 (25.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (25.0%)
High0 (0.0%)
None3 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-5195HIGH Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature | Nov 10, 2016 | 7.0 | 95 | YES | YES |
CVE-2016-2518MEDIUM The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode | Jan 30, 2017 | 5.3 | 26 | NO | NO |
CVE-2016-6667CRITICAL NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to execute arbitrary code via unspec | Feb 7, 2017 | 9.8 | 25 | NO | NO |
CVE-2017-14053HIGH NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, which makes it easier for remote | Sep 1, 2017 | 7.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
1 CVE
25.0% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
25.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Oncommand Unified Manager For Clustered Data Ontap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.4 | 1 | 9.8 | 2.9% | 0 | 0 |
| 6.3 | 1 | 9.8 | 2.9% | 0 | 0 |