CVE-2008-3349

CRITICAL

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash...

Affects 3 products across 2 vendors.

BCS7.78
CVSS 2.010.0
EPSS3.4%
Percentile88th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-264: Permissions, Privileges, and Access Controls

Broad class covering failures in permission enforcement. Deprecated in favor of CWE-284, CWE-862, CWE-863.

◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2008. A critical vulnerability affects Ibm systems (CVE-2008-3349). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2008-GLOBAL-021643-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-3349?
This vulnerability was disclosed in 2008. A critical vulnerability affects Ibm systems (CVE-2008-3349). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2008-3349?
CVE-2008-3349 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.4%.
Is CVE-2008-3349 actively exploited?
No confirmed active exploitation of CVE-2008-3349 as of 2026-05-30.
How do I remediate CVE-2008-3349?
Priority: MEDIUM.
What systems are affected by CVE-2008-3349?
CVE-2008-3349 affects: Ibm, Netapp, Netapp.
Vulnerability Details
CVE IDCVE-2008-3349
BSIDBS-2008-GLOBAL-021643-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2008-07-28
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
SourceNVD
Official Description

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Ibm N Series Storage Server
Netapp Data Ontap
Netapp Fas900
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 6571 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashae8c4443625dfc2c83530ba2e6ab4af9cde7d1e2124fccfe91455cf37b01ed4f033ed241d7427675c6dfe0de1faf52720532f484c2353bd4b431d006f2b10881
Related CVEs affecting Ibm
CVE-2001-0554 10.0 Buffer overflow in BSD-based telnetd telnet daemon on various operating syste... CVE-2006-5008 10.0 Unspecified vulnerability in utape in IBM AIX 5.2.0 and 5.3.0 allows attacker... CVE-2002-0679 10.0 Buffer overflow in Common Desktop Environment (CDE) ToolTalk RPC database ser... CVE-2002-0743 10.0 mail and mailx in AIX 4.3.3 core dump when called with a very long argument, ... CVE-2002-0744 10.0 namerslv in AIX 4.3.3 core dumps when called with a very long argument, possi...
View all Ibm CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →