Failure to Enable SMB Signing Enforcement in NetApp Clustered Data ONTAP: A Gateway for Man-in-the-Middle Attacks and Privilege Escalation

Failure to Enable SMB Signing Enforcement in NetApp Clustered Data ONTAP: A Gateway for Man-in-the-Middle Attacks and Privilege Escalation

CVE-2016-3997 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.

Learn more about our Web Application Penetration Testing UK.