PatchSiren cyber security CVE debrief
CVE-2016-6495 Netapp CVE debrief
CVE-2016-6495 is a medium-severity information disclosure issue in NetApp Data ONTAP before 8.2.4P5 when operating in 7-Mode. According to NVD, a remote attacker can obtain information about the volumes configured for HTTP access. This is a confidentiality impact only issue, but it affects a network-reachable service path and does not require privileges or user interaction.
- Vendor
- Netapp
- Product
- Unknown
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-07
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-07
- Advisory updated
- 2026-05-13
Who should care
Administrators and security teams responsible for NetApp Data ONTAP 7-Mode systems, especially environments that still expose HTTP access on volumes or have legacy storage management services in production.
Technical summary
NVD classifies this issue as CVSS 3.0: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N with CWE-200. The vulnerable condition is limited to Data ONTAP before 8.2.4P5 in 7-Mode. The issue allows remote disclosure of information about volumes configured for HTTP access, making it a confidentiality exposure rather than an integrity or availability flaw.
Defensive priority
Moderate. Prioritize remediation for any 7-Mode deployment that is still in service, especially if HTTP access is enabled or reachable from untrusted networks. The issue is not listed as KEV, but it is a direct information disclosure vector with no authentication requirement.
Recommended defensive actions
- Upgrade NetApp Data ONTAP to 8.2.4P5 or later, following the vendor advisory.
- Review whether HTTP access is actually needed for any volumes, and disable or restrict it where possible.
- Limit network exposure to storage and management interfaces so only trusted administrative networks can reach them.
- Inventory remaining Data ONTAP 7-Mode systems and include them in legacy-technology risk tracking.
- Validate patch status against the NetApp advisory and confirm affected systems are not running versions before 8.2.4P5.
Evidence notes
The supplied NVD record states that CVE-2016-6495 affects NetApp Data ONTAP before 8.2.4P5 in 7-Mode and permits remote attackers to obtain information about volumes configured for HTTP access. NVD also provides CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N and CWE-200. The only vendor reference supplied is the NetApp knowledge base advisory NTAP-20160929-0001, labeled as Patch/Vendor Advisory.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-6495 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-6495
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-6495 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6495
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://kb.netapp.com/support/s/article/NTAP-20160929-0001
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.