Impact
This vulnerability arises from improper handling of the Relying Party ID in WebAuthn multi‑factor authentication on NETAPP ONTAP 9.16.1 and later. The flaw permits an attacker who already possesses valid user credentials to bypass the MFA step, effectively logging in as if the second authentication layer had succeeded. This authentication weakness is identified as CWE‑288 and can result in unauthorized access and privilege escalation.
Affected Systems
NETAPP ONTAP 9 releases 9.16.1 and newer that have WebAuthn MFA configured. Earlier ONTAP versions or configurations without WebAuthn MFA are not affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score of less than 1 % suggests a low probability of exploitation at this time, and the vulnerability is not listed in CISA's KEV catalog. Exploitation likely requires only that an attacker has valid credentials; the description infers that an attacker who has obtained or guessed a legitimate username and password could bypass MFA without further privileges or internal access.
OpenCVE Enrichment