CVE-2016-3997: Netapp Clustered Data Ontap

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.

Affected products

  • Netapp Clustered Data Ontap: version 8.3.1 only

Published 2017-07-03. Last modified 2026-06-17.