NetApp published this final advisory covering CVE-2021-41090, CVE-2021-43798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-44420; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-43527; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-42550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp Service Level Manager; Snap Creator Framework.
NetApp published this final advisory covering CVE-2021-41805; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-25020; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-44790, CVE-2021-44224; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-20470, CVE-2021-20493, CVE-2021-29716, CVE-2021-29719, CVE-2021-29756, CVE-2021-29867, CVE-2021-38909; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-41244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-4104; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27007; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Virtual Desktop Service (VDS).
NetApp published this final advisory covering CVE-2021-23732; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-21707; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).
NetApp published this final advisory covering CVE-2017-5123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.
NetApp published this final advisory covering CVE-2021-27006; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2021-45105; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere.
NetApp published this final advisory covering CVE-2021-45046; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.
NetApp published this final advisory covering CVE-2021-43975, CVE-2021-43976; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this interim advisory covering CVE-2021-41771, CVE-2021-41772; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-33058, CVE-2021-33059, CVE-2021-33098; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-0197, CVE-2021-0198, CVE-2021-0199, CVE-2021-0200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-0146; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-44228; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Cloud Insights Acquisition Unit; Cloud Manager; Cloud Secure Agent; NetApp SolidFire, Enterprise SDS & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere; OnCommand Insight; SnapCenter Plug-in for VMware vSphere.
NetApp published this final advisory covering CVE-2021-43616; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2016-2124, CVE-2020-25717, CVE-2020-25718, CVE-2020-25719, CVE-2020-25721, CVE-2020-25722, CVE-2021-23192, CVE-2021-3738; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-8921, CVE-2019-8922; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-41229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3715; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-25742; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-23718; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-43267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.
NetApp published this final advisory covering CVE-2021-43057; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-41174; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22096; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; MetroCluster Tiebreaker for clustered Data ONTAP; OnCommand Insight; Snap Creator Framework; SnapCenter.
NetApp published this final advisory covering CVE-2011-1075; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-42739; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-42327; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-38297; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-25219; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-21703; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).
NetApp published this final advisory covering CVE-2021-32028, CVE-2021-32029; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-4951, CVE-2021-29679, CVE-2021-29745; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2018-25010, CVE-2018-25012, CVE-2018-25013, CVE-2020-36328, CVE-2020-36329, CVE-2020-36331; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-0157, CVE-2021-0158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-42252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-22930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-32628, CVE-2021-41099, CVE-2021-32672, CVE-2021-32762, CVE-2021-32626, CVE-2021-32627, CVE-2021-32765, CVE-2021-32687, CVE-2021-32675; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2018-25009, CVE-2018-25011, CVE-2018-25014, CVE-2020-36330, CVE-2020-36332; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-42340; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2021-42008; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-36222; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-3580; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-3520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-33910; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-22945, CVE-2021-22946, CVE-2021-22947; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-21704, CVE-2021-21705; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9 (formerly Clustered Data ONTAP).
NetApp published this final advisory covering CVE-2021-29825, CVE-2021-29763; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-42013, CVE-2021-41773, CVE-2021-41524; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-39226; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27005; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-27004; the API labels exploitation information as **Not public**. The API currently lists affected products as: System Manager 9.x.
NetApp published this final advisory covering CVE-2021-23449; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-21706; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-36090, CVE-2021-35515, CVE-2021-35516, CVE-2021-35517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Insights Acquisition Unit; OnCommand Insight.
NetApp published this final advisory covering CVE-2021-35597; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.
NetApp published this final advisory covering CVE-2021-20305; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-27001; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-41073; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-25740; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-8561; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2016-20012; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27003; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-27002; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-34798, CVE-2021-36160, CVE-2021-39275, CVE-2021-40438; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2021-41079; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2021-40839; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-38300; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-25741; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22147; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-19143, CVE-2020-19144; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-3634; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-25737; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-16871; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-37750; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-3713; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29631; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-29630; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this interim advisory covering CVE-2021-39139, CVE-2021-39140, CVE-2021-39141, CVE-2021-39144, CVE-2021-39145, CVE-2021-39146, CVE-2021-39147, CVE-2021-39148, CVE-2021-39149, CVE-2021-39150, CVE-2021-39151, CVE-2021-39152, CVE-2021-39153, CVE-2021-39154; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-22931, CVE-2021-22940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-37576; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-33193; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-31810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-30468; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22939; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-5398; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Data Availability Services; SnapCenter.
NetApp published this final advisory covering CVE-2021-36770; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; Snap Creator Framework.
NetApp published this final advisory covering CVE-2021-25218; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2020-22403; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-32785, CVE-2021-32786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-38207; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-37600; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-3682; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-33195; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent.
NetApp published this final advisory covering CVE-2021-29657; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2012-2666; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28966, CVE-2021-31799, CVE-2021-32066; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22144, CVE-2021-22145; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-30639, CVE-2021-30640, CVE-2021-33037; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2021-0002, CVE-2021-0003, CVE-2021-0084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-0004, CVE-2021-0005, CVE-2021-0006, CVE-2021-0007, CVE-2021-0008, CVE-2021-0009; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-35942; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-32761; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2021-26118; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2020-10771; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2020-10727; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2021-27792, CVE-2021-27791, CVE-2021-27790, CVE-2021-27789, CVE-2020-15388, CVE-2020-15386, CVE-2020-15383; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.
NetApp published this final advisory covering CVE-2021-27793, CVE-2021-27794; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.
NetApp published this final advisory covering CVE-2021-36373, CVE-2021-36374; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.
NetApp published this final advisory covering CVE-2021-37159; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-34429; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine.
NetApp published this final advisory covering CVE-2021-22146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-35039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-34558; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident; Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2021-34428; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SANtricity Cloud Connector; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-32078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-31535; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-22904, CVE-2021-22880, CVE-2021-22885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3592, CVE-2021-3593, CVE-2021-3594, CVE-2021-3595; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22918, CVE-2021-22921; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this interim advisory covering CVE-2021-3541; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapManager for Hyper-V.
NetApp published this final advisory covering CVE-2021-35042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28691; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-26999; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-26998; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2020-28097; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2017-20005; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).
NetApp published this final advisory covering CVE-2021-33203, CVE-2021-33571; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-31618; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-28169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Management Services for Element Software and NetApp HCI; Snap Creator Framework.
NetApp published this final advisory covering CVE-2021-20293; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2020-36387; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-25097; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2019-12067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2013-4536; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2002-2438; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2019-17543, CVE-2021-22884, CVE-2021-22901, CVE-2021-2339, CVE-2021-2340, CVE-2021-2342, CVE-2021-2352, CVE-2021-2354, CVE-2021-2356, CVE-2021-2357, CVE-2021-2367, CVE-2021-2370, CVE-2021-2372, CVE-2021-2374, CVE-2021-2383, CVE-2021-2384, CVE-2021-2385, CVE-2021-2387, CVE-2021-2389, CVE-2021-2390, CVE-2021-2399, CVE-2021-2402, CVE-2021-2410, CVE-2021-2411, CVE-2021-2412, CVE-2021-2417, CVE-2021-2418, CVE-2021-2422, CVE-2021-2424, CVE-2021-2425, CVE-2021-2426, CVE-2021-2427, CVE-2021-2429, CVE-2021-2437, CVE-2021-2440, CVE-2021-2441, CVE-2021-2444; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this interim advisory covering CVE-2021-2388, CVE-2021-2369, CVE-2021-2432, CVE-2021-2341; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-3544, CVE-2021-3545, CVE-2021-3546, CVE-2020-35503; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-4885, CVE-2020-4945, CVE-2021-20579, CVE-2021-29703, CVE-2021-29777; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29702; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20461; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-20181; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-7469; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2020-36385; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-27661; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2018-25015; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-28651, CVE-2021-31806, CVE-2021-31807, CVE-2021-31808; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2020-25709, CVE-2020-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-3489, CVE-2021-3490, CVE-2021-3491; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-3530; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-26707; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-0129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-0051; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2020-35504, CVE-2020-35505, CVE-2020-35506; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-32027; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29629; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29628; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22118; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.
NetApp published this final advisory covering CVE-2020-14326; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-3527; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-30465; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29505; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-23017; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-22543; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-20221; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20196; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-10701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3559; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-33587; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-33502; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-33200; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-32640; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-31440; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-10688; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25670, CVE-2020-25671, CVE-2020-25672, CVE-2020-25673; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2019-17567, CVE-2020-13938, CVE-2020-13950, CVE-2020-35452, CVE-2021-26690, CVE-2021-26691, CVE-2021-30641; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-33623; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2020-25724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3483; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.
NetApp published this final advisory covering CVE-2021-3426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility; SnapCenter.
NetApp published this final advisory covering CVE-2021-33574; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-22138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-14301; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-4588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3517, CVE-2021-3518, CVE-2021-3537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Antivirus Connector; ONTAP Select Deploy administration utility; SnapDrive for Unix; SnapDrive for Windows.
NetApp published this final advisory covering CVE-2021-22135, CVE-2021-22137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-33204; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-32606; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-23134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-0095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2020-27830; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-24516; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this interim advisory covering CVE-2020-13529; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2019-4471, CVE-2019-4653, CVE-2019-4722, CVE-2019-4723, CVE-2019-4724, CVE-2019-4730, CVE-2020-4300, CVE-2020-4354, CVE-2020-4520, CVE-2020-4561; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2020-14550, CVE-2021-2006, CVE-2021-2007, CVE-2021-2010, CVE-2021-2011; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2021-32399; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-29921; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp XCP NFS; NetApp XCP SMB; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-29491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29489; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2020-15522; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; SnapCenter.
NetApp published this final advisory covering CVE-2021-3501; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this interim advisory covering CVE-2021-31879; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-31597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-31542; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-23383; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-21414; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-35519; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-24511, CVE-2020-24512; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp SolidFire BIOS.
NetApp published this final advisory covering CVE-2020-8703, CVE-2020-24506, CVE-2020-24507; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-3506; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-32052; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-31231; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29469; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27905; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-24509; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-28163, CVE-2021-28164, CVE-2021-28165; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; NetApp BlueXP; NetApp E-Series Performance Analyzer; NetApp SANtricity Cloud Connector; NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter; SnapCenter Plug-in for VMware vSphere/BlueXP backup and Recovery for Virtual Machine; Storage Replication Adapter for Clustered Data ONTAP for VMware vSphere 9.7 and above.
NetApp published this final advisory covering CVE-2021-26997; the API labels exploitation information as **Not public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.
NetApp published this final advisory covering CVE-2021-26996; the API labels exploitation information as **Not public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.
NetApp published this final advisory covering CVE-2021-26995; the API labels exploitation information as **Not public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.
NetApp published this final advisory covering CVE-2021-26993; the API labels exploitation information as **Not public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.
NetApp published this final advisory covering CVE-2021-21295, CVE-2021-21409; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand API Services; OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2021-29662; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); SnapCenter.
NetApp published this final advisory covering CVE-2021-29424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2021-29418; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29154; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire & HCI Management Node; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-26073; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-23369; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-36313; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-15225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29943, CVE-2021-29262; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-26994; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-3507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-30638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28658; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27850; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-26296; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-21267; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer; OnCommand Insight.
NetApp published this final advisory covering CVE-2021-20289; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-20197; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-35521, CVE-2020-35522, CVE-2020-35523, CVE-2020-35524; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-28957; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2021-20284; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-27825; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-27783; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2020-17516; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-13946; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2020-12762; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-25214, CVE-2021-25215, CVE-2021-25216; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S.
NetApp published this final advisory covering CVE-2021-29266; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-28092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27358; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-23926; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Unified Manager Core Package; Snap Creator Framework; SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-23901; the API labels exploitation information as **Public**. The API currently lists affected products as: Snap Creator Framework.
NetApp published this final advisory covering CVE-2020-5421; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight; Snap Creator Framework; SnapCenter.
NetApp published this final advisory covering CVE-2020-13954; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp VASA Provider for Clustered Data ONTAP 9.7 and above; Snap Creator Framework.
NetApp published this final advisory covering CVE-2020-1971, CVE-2021-3449, CVE-2020-28196, CVE-2021-23841, CVE-2021-2144, CVE-2021-2172, CVE-2021-2298, CVE-2021-2178, CVE-2021-2202, CVE-2021-2307, CVE-2021-2304, CVE-2021-2180, CVE-2021-2194, CVE-2021-2154, CVE-2021-2166, CVE-2021-2196, CVE-2021-2300, CVE-2021-2305, CVE-2021-2179, CVE-2021-2226, CVE-2021-2160, CVE-2021-2164, CVE-2021-2169, CVE-2021-2170, CVE-2021-2193, CVE-2021-2203, CVE-2021-2212, CVE-2021-2213, CVE-2021-2278, CVE-2021-2299, CVE-2021-2230, CVE-2021-2146, CVE-2021-2201, CVE-2021-2208, CVE-2021-2215, CVE-2021-2217, CVE-2021-2293, CVE-2021-2174, CVE-2021-2171, CVE-2021-2162, CVE-2021-2301, CVE-2021-2308, CVE-2021-2232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this interim advisory covering CVE-2021-2161, CVE-2021-2163; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Cloud Secure Agent; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2021-3392, CVE-2021-3409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3393; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28660; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-28657; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20255; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-36309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-25031, CVE-2019-25032, CVE-2019-25033, CVE-2019-25034, CVE-2019-25035, CVE-2019-25036, CVE-2019-25037, CVE-2019-25038, CVE-2019-25039, CVE-2019-25040, CVE-2019-25041, CVE-2019-25042; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-3416, CVE-2021-20263; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-21341, CVE-2021-21342, CVE-2021-21343, CVE-2021-21344, CVE-2021-21345, CVE-2021-21346, CVE-2021-21347, CVE-2021-21348, CVE-2021-21349, CVE-2021-21350, CVE-2021-21351; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2019-10127, CVE-2019-10128; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-28951, CVE-2021-28952, CVE-2021-28964, CVE-2021-28971, CVE-2021-28972; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-28147, CVE-2021-28148; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22134; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29627; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-29626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25581; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25578, CVE-2020-25579; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22883, CVE-2021-22884; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-20231, CVE-2021-20232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-3444; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-28153; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware.
NetApp published this final advisory covering CVE-2020-14372; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28038, CVE-2021-28039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-4976, CVE-2020-5024, CVE-2020-5025; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2021-25329, CVE-2021-25122; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Storage Workload Security Agent; Element Plug-in for vCenter Server.
NetApp published this final advisory covering CVE-2020-26258, CVE-2020-26259; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-26217; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-3189; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this interim advisory covering CVE-2021-28375; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-20226; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2020-27618; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-27543; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-27223; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node; SANtricity Storage Plugin for vCenter; Snap Creator Framework; SnapCenter; SnapManager for Oracle; SnapManager for SAP.
NetApp published this final advisory covering CVE-2021-20277, CVE-2020-27840; the API labels exploitation information as **Not public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-23336; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); ONTAP Select Deploy administration utility; SnapCenter.
NetApp published this final advisory covering CVE-2021-20229; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-20194; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2021-27185, CVE-2021-27191; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-27218, CVE-2021-27219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer.
NetApp published this final advisory covering CVE-2021-27212; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H300E/H500E/H700E/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-8625; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup (formerly AltaVault).
NetApp published this final advisory covering CVE-2020-7021; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-26992; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-26991; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-26990; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-26987; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; Management Services for Element Software and NetApp HCI; NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2020-14058, CVE-2020-14059, CVE-2020-15049; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2020-7071, CVE-2021-21702; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2020-28500, CVE-2021-23337; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; System Manager 9.x.
NetApp published this final advisory covering CVE-2021-21315; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-35517; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-17380; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-15523; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2020-8449, CVE-2020-8450, CVE-2020-8517; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-3326; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2021-26117; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Workflow Automation.
NetApp published this final advisory covering CVE-2020-9492; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-29443; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-16119; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-11945; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-26989; the API labels exploitation information as **Public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-26988; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-21284, CVE-2021-21285; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x.
NetApp published this final advisory covering CVE-2021-3281; the API labels exploitation information as **Public**. The API currently lists affected products as: SnapCenter.
NetApp published this final advisory covering CVE-2021-3177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP 9 (formerly Clustered Data ONTAP); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-28488; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-15810, CVE-2020-15811, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2020-15811, CVE-2020-15810, CVE-2020-24606; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2021-1998, CVE-2021-2001, CVE-2021-2002, CVE-2021-2009, CVE-2021-2012, CVE-2021-2014, CVE-2021-2016, CVE-2021-2019, CVE-2021-2020, CVE-2021-2021, CVE-2021-2022, CVE-2021-2024, CVE-2021-2028, CVE-2021-2030, CVE-2021-2031, CVE-2021-2032, CVE-2021-2036, CVE-2021-2038, CVE-2021-2042, CVE-2021-2046, CVE-2021-2048, CVE-2021-2055, CVE-2021-2056, CVE-2021-2058, CVE-2021-2060, CVE-2021-2061, CVE-2021-2065, CVE-2021-2070, CVE-2021-2072, CVE-2021-2076, CVE-2021-2081, CVE-2021-2087, CVE-2021-2088, CVE-2021-2122; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.
NetApp published this final advisory covering CVE-2021-3114, CVE-2021-3115; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Insights Telegraf Agent; StorageGRID (formerly StorageGRID Webscale).
NetApp published this final advisory covering CVE-2021-3121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-22132; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-21252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); SnapCenter.
NetApp published this final advisory covering CVE-2021-20190; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager; OnCommand API Services; OnCommand Insight.
NetApp published this final advisory covering CVE-2020-28374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-8265, CVE-2020-8287; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-28851, CVE-2020-28852; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-24492, CVE-2020-24493, CVE-2020-24494, CVE-2020-24495, CVE-2020-24496, CVE-2020-24497, CVE-2020-24498, CVE-2020-24500, CVE-2020-24501, CVE-2020-24505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2021-24122; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server.
NetApp published this final advisory covering CVE-2020-36158; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-11947; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-8578; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2020-8587; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand System Manager 9.x.
NetApp published this final advisory covering CVE-2020-8578; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2019-12519, CVE-2019-12520, CVE-2019-12521, CVE-2019-12522, CVE-2019-12524; the API labels exploitation information as **Public**. The API currently lists affected products as: Cloud Manager.
NetApp published this final advisory covering CVE-2020-36179, CVE-2020-36180, CVE-2020-36181, CVE-2020-36182, CVE-2020-36183, CVE-2020-36184, CVE-2020-36185, CVE-2020-36186, CVE-2020-36187, CVE-2020-36188, CVE-2020-36189; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.
NetApp published this final advisory covering CVE-2020-27846; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-25013; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2019-20808; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-25066, CVE-2020-27337, CVE-2020-27338, CVE-2020-27336; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-8589; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2020-8588; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2021-23239, CVE-2021-23240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node.
NetApp published this final advisory covering CVE-2020-29509, CVE-2020-29510, CVE-2020-29511; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident.
NetApp published this final advisory covering CVE-2020-4642; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-35728; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.
NetApp published this final advisory covering CVE-2020-35448; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-11724; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-10663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2019-19462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); NetApp SolidFire Baseboard Management Controller (BMC); NetApp SteelStore Cloud Integrated Storage.
NetApp published this final advisory covering CVE-2019-17006; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2021-3156; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.
NetApp published this final advisory covering CVE-2020-8585; the API labels exploitation information as **Not public**. The API currently lists affected products as: OnCommand Unified Manager Core Package.
NetApp published this final advisory covering CVE-2020-8764, CVE-2020-8738, CVE-2020-8740, CVE-2020-8739; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Compute Node BIOS; NetApp HCI Storage Node BIOS; NetApp SolidFire BIOS.
NetApp published this final advisory covering CVE-2020-29660, CVE-2020-29661; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400; NetApp Cloud Backup (formerly AltaVault); NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-8563, CVE-2020-8564, CVE-2020-8566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-29562, CVE-2020-29573; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-16593, CVE-2020-16599; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-35490, CVE-2020-35491; the API labels exploitation information as **Public**. The API currently lists affected products as: Element Plug-in for vCenter Server; NetApp Cloud Backup (formerly AltaVault); NetApp Service Level Manager.
NetApp published this final advisory covering CVE-2020-27786; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-8581; the API labels exploitation information as **Not public**. The API currently lists affected products as: Clustered Data ONTAP.
NetApp published this final advisory covering CVE-2020-16590, CVE-2020-16591, CVE-2020-16592, CVE-2020-16598; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); ONTAP Select Deploy administration utility.
NetApp published this final advisory covering CVE-2020-27821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-27730; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in).
NetApp published this final advisory covering CVE-2020-25613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-17531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-17530; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.
NetApp published this final advisory covering CVE-2020-8584; the API labels exploitation information as **Not public**. The API currently lists affected products as: NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).
NetApp published this final advisory covering CVE-2020-4135; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.
NetApp published this final advisory covering CVE-2020-27350; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-25692; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault); NetApp SolidFire Baseboard Management Controller (BMC).
NetApp published this final advisory covering CVE-2020-25649; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Service Level Manager; OnCommand API Services; OnCommand Workflow Automation; Snap Creator Framework.
NetApp published this interim advisory covering CVE-2015-9251; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).