CVE-2016-6904: Netapp Vasa Provider

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.

Affected products

  • Netapp Vasa Provider: up to and including 7.0

Published 2017-12-11. Last modified 2026-06-17.