Network Appliance Data ONTAP 7.0 and earlier allows iSCSI Initiators to bypass iSCSI authentication via a modified client that skips the Security (Start) mode, as required by the Login Negotiation protocol, and uses Operational mode without proving identity.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=bugtraq&m=113028385702680&w=2 - | |
References | () http://secunia.com/advisories/17321 - Patch | |
References | () http://securitytracker.com/id?1015103 - | |
References | () http://www.matasano.com/advisories/netapp-iSCSI.txt - | |
References | () http://www.securityfocus.com/bid/15197 - | |
References | () http://www.vupen.com/english/advisories/2005/2193 - |
Information
Published : 2005-10-27 10:02
Updated : 2024-11-21 00:01
NVD link : CVE-2005-3327
Mitre link : CVE-2005-3327
CVE.ORG link : CVE-2005-3327
JSON object : View
Products Affected
network_appliance
- data_ontap
CWE