CVE-2016-6904: Netapp Vasa Provider
High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.
Affected products
- Netapp Vasa Provider: up to and including 7.0
Published 2017-12-11. Last modified 2026-06-17.