CVE-2016-6904
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentication. This could allow an unauthenticated attacker to obtain authentication credentials.
Affected products
NetApp · VASA Provider for Clustered Data ONTAP