CVE-2019-5506: Netapp Clustered Data Ontap

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks.

Affected products

  • Netapp Clustered Data Ontap: from 9.0, up to and including 9.6; version 9.6 only

Published 2019-10-09. Last modified 2026-06-17.