// For flags

CVE-2024-21988

CVE-2024-21988 SSH Cryptographic Implementation Vulnerability in StorageGRID (formerly StorageGRID Webscale)

Severity Score

5.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

StorageGRID (formerly StorageGRID Webscale) versions prior to 11.7.0.9 and 11.8.0.5 are susceptible to disclosure of sensitive information via complex MiTM attacks due to a vulnerability in the SSH cryptographic implementation.

Las versiones de StorageGRID (anteriormente StorageGRID Webscale) anteriores a 11.7.0.9 y 11.8.0.5 son susceptibles a la divulgación de información confidencial a través de ataques MiTM complejos debido a una vulnerabilidad en la implementación criptográfica SSH.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
High
Authentication
None
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-01-03 CVE Reserved
  • 2024-06-14 CVE Published
  • 2024-11-12 CVE Updated
  • 2025-03-31 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
NetApp
Search vendor "NetApp"
StorageGRID (formerly StorageGRID Webscale)
Search vendor "NetApp" for product "StorageGRID (formerly StorageGRID Webscale)"
< 11.7.0.9
Search vendor "NetApp" for product "StorageGRID (formerly StorageGRID Webscale)" and version " < 11.7.0.9"
en
Affected
NetApp
Search vendor "NetApp"
StorageGRID (formerly StorageGRID Webscale)
Search vendor "NetApp" for product "StorageGRID (formerly StorageGRID Webscale)"
< 11.8.0.5
Search vendor "NetApp" for product "StorageGRID (formerly StorageGRID Webscale)" and version " < 11.8.0.5"
en
Affected