Unfortunately it is not so simple.
First of all you must determine WHEN the password was changed and then, if still existing on the filer, analyze the logs to see if something is reported.
On that version of ONTAP not everything was tracked and most of the things were not built considering the security (ssh was not the only method to access).