Does CVE-2021-4034 affect the NetApp environment?
Applies to
- Cloud Volumes ONTAP (CVO)
- Linux OS
- Cybersecurity
Answer
From the available information, this appears to be a local privilege escalation in PolicyKit (also known as "polkit") giving unprivileged users admin rights on a target machine.
None of NetApp's appliances and other Linux shipping products are set up to allow unprivileged user logins, but NetApp will send evaluations according to standard process.
If a NetApp app is installed on a user-managed Linux system then the user should be checking with the Linux distribution vendor for information.