PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6495 Netapp CVE debrief

CVE-2016-6495 is a medium-severity information disclosure issue in NetApp Data ONTAP before 8.2.4P5 when operating in 7-Mode. According to NVD, a remote attacker can obtain information about the volumes configured for HTTP access. This is a confidentiality impact only issue, but it affects a network-reachable service path and does not require privileges or user interaction.

Vendor
Netapp
Product
Unknown
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-07
Original CVE updated
2026-05-13
Advisory published
2017-02-07
Advisory updated
2026-05-13

Who should care

Administrators and security teams responsible for NetApp Data ONTAP 7-Mode systems, especially environments that still expose HTTP access on volumes or have legacy storage management services in production.

Technical summary

NVD classifies this issue as CVSS 3.0: AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N with CWE-200. The vulnerable condition is limited to Data ONTAP before 8.2.4P5 in 7-Mode. The issue allows remote disclosure of information about volumes configured for HTTP access, making it a confidentiality exposure rather than an integrity or availability flaw.

Defensive priority

Moderate. Prioritize remediation for any 7-Mode deployment that is still in service, especially if HTTP access is enabled or reachable from untrusted networks. The issue is not listed as KEV, but it is a direct information disclosure vector with no authentication requirement.

Recommended defensive actions

  • Upgrade NetApp Data ONTAP to 8.2.4P5 or later, following the vendor advisory.
  • Review whether HTTP access is actually needed for any volumes, and disable or restrict it where possible.
  • Limit network exposure to storage and management interfaces so only trusted administrative networks can reach them.
  • Inventory remaining Data ONTAP 7-Mode systems and include them in legacy-technology risk tracking.
  • Validate patch status against the NetApp advisory and confirm affected systems are not running versions before 8.2.4P5.

Evidence notes

The supplied NVD record states that CVE-2016-6495 affects NetApp Data ONTAP before 8.2.4P5 in 7-Mode and permits remote attackers to obtain information about volumes configured for HTTP access. NVD also provides CVSS 3.0 vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N and CWE-200. The only vendor reference supplied is the NetApp knowledge base advisory NTAP-20160929-0001, labeled as Patch/Vendor Advisory.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6495 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6495

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6495 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6495

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.