CVE-2019-5502: Netapp Data Ontap

Critical severity, CVSS 9.1. EPSS: 0.9% chance of exploitation in the next 30 days.

SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data.

Affected products

  • Netapp Data Ontap: before 8.2.5 (fixed in 8.2.5); version 8.2.5 only

Published 2019-08-05. Last modified 2026-06-17.