CVE-2019-5492: Netapp Element Plug-In For vCenter Server

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

Element Plug-in for vCenter Server versions prior to 4.2.3 may disclose sensitive account information to an unauthenticated attacker. NetApp HCI Compute Node versions prior to 1.4P2 bundle affected versions of Element Plug-in for vCenter Server.

Affected products

  • Netapp Element Plug-In For vCenter Server: before 4.2.3 (fixed in 4.2.3)
  • Netapp Hyper Converged Infrastructure Compute Node: up to and including 1.4

Published 2019-04-29. Last modified 2026-06-17.