CVE-2024-21982: Netapp Clustered Data Ontap

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

ONTAP versions 9.4 and higher are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information to unprivileged attackers when the object-store profiler command is being run by an administrative user.

Affected products

  • Netapp Clustered Data Ontap: from 9.4, before 9.8 (fixed in 9.8); version 9.8 only; version 9.9.1 only; version 9.10.1 only; version 9.11.1 only; version 9.12.1 only; …

Published 2024-01-12. Last modified 2026-06-17.