Content Library · Advisory

Advisory 2023

Browse 560 2023 NetApp advisory records in the NetApp Black Box content library. Page 4 of 5.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2023-1550 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0008/

NetApp published this final advisory covering CVE-2023-1550; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-1544 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0005/

NetApp published this final advisory covering CVE-2023-1544; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1380 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0001/

NetApp published this final advisory covering CVE-2023-1380; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1077 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0002/

NetApp published this interim advisory covering CVE-2023-1077; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0179 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0003/

NetApp published this final advisory covering CVE-2023-0179; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3162 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0004/

NetApp published this final advisory covering CVE-2022-3162; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230511-0010/

NetApp published this final advisory covering CVE-2023-26021, CVE-2023-26022, CVE-2023-27559, CVE-2023-29255, CVE-2023-29257, CVE-2023-25930, CVE-2023-27555; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26604 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0009/

NetApp published this final advisory covering CVE-2023-26604; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-26464 Apache Log4j Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0008/

NetApp published this interim advisory covering CVE-2023-26464; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24999 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0001/

NetApp published this final advisory covering CVE-2023-24999; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20860 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0006/

NetApp published this final advisory covering CVE-2023-20860; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-1252 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0005/

NetApp published this final advisory covering CVE-2023-1252; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-1078 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0004/

NetApp published this final advisory covering CVE-2023-1078; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48424 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0002/

NetApp published this final advisory covering CVE-2022-48424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48423 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0003/

NetApp published this final advisory covering CVE-2022-48423; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-3294 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0007/

NetApp published this final advisory covering CVE-2022-3294; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3116 Heimdal Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230505-0010/

NetApp published this final advisory covering CVE-2022-3116; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28772 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0005/

NetApp published this final advisory covering CVE-2023-28772; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-28466 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0006/

NetApp published this final advisory covering CVE-2023-28466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-27475 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0003/

NetApp published this final advisory covering CVE-2023-27475; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-21971 MySQL Connector/J Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0010/

NetApp published this final advisory covering CVE-2023-21971; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2023-1281 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0004/

NetApp published this final advisory covering CVE-2023-1281; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0482 RESTEasy Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0001/

NetApp published this final advisory covering CVE-2023-0482; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-0812 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0011/

NetApp published this final advisory covering CVE-2022-0812; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-39537 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0012/

NetApp published this interim advisory covering CVE-2021-39537; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; NetApp Cloud Backup (formerly AltaVault); NetApp E-Series Performance Analyzer; NetApp SolidFire & HCI Management Node.

Open source
Advisory

April 2023 MySQL Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0007/

NetApp published this final advisory covering CVE-2022-37434, CVE-2022-43548, CVE-2022-43551, CVE-2023-0215, CVE-2023-21911, CVE-2023-21912, CVE-2023-21913, CVE-2023-21917, CVE-2023-21919, CVE-2023-21920, CVE-2023-21929, CVE-2023-21933, CVE-2023-21935, CVE-2023-21940, CVE-2023-21945, CVE-2023-21946, CVE-2023-21947, CVE-2023-21953, CVE-2023-21955, CVE-2023-21962, CVE-2023-21963, CVE-2023-21966, CVE-2023-21971, CVE-2023-21972, CVE-2023-21976, CVE-2023-21977, CVE-2023-21980, CVE-2023-21982; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2023 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230427-0008/

NetApp published this interim advisory covering CVE-2023-21930, CVE-2023-21937, CVE-2023-21938, CVE-2023-21939, CVE-2023-21954, CVE-2023-21967, CVE-2023-21968; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp SolidFire & HCI Management Node; OnCommand Insight.

Open source
Advisory

March 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0010/

NetApp published this interim advisory covering CVE-2023-27535, CVE-2023-27536, CVE-2023-27537, CVE-2023-27538; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

March 2023 Sudo Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0002/

NetApp published this interim advisory covering CVE-2023-28486, CVE-2023-28487; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-27534 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0012/

NetApp published this final advisory covering CVE-2023-27534; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-27533 cURL/libcURL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0011/

NetApp published this final advisory covering CVE-2023-27533; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-27490 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0006/

NetApp published this final advisory covering CVE-2023-27490; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20861 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0007/

NetApp published this final advisory covering CVE-2023-20861; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2023-1410 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0003/

NetApp published this final advisory covering CVE-2023-1410; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1390 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0001/

NetApp published this final advisory covering CVE-2023-1390; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0386 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0004/

NetApp published this final advisory covering CVE-2023-0386; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4095 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0005/

NetApp published this final advisory covering CVE-2022-4095; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-2097 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230420-0008/

NetApp published this final advisory covering CVE-2022-2097; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

March 2023 OpenSSL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230414-0001/

NetApp published this interim advisory covering CVE-2023-0465, CVE-2023-0466; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-28531 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0008/

NetApp published this final advisory covering CVE-2023-28531; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28425 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0005/

NetApp published this final advisory covering CVE-2023-28425; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28155 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0007/

NetApp published this final advisory covering CVE-2023-28155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27320 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0009/

NetApp published this final advisory covering CVE-2023-27320; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-26053 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0002/

NetApp published this final advisory covering CVE-2023-26053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-22462 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0004/

NetApp published this final advisory covering CVE-2023-22462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-1118 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0003/

NetApp published this final advisory covering CVE-2023-1118; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0507 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0001/

NetApp published this final advisory covering CVE-2023-0507; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0030 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0010/

NetApp published this final advisory covering CVE-2023-0030; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48425 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230413-0006/

NetApp published this final advisory covering CVE-2022-48425; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

March 2023 Samba Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0007/

NetApp published this final advisory covering CVE-2023-0614, CVE-2023-0922, CVE-2023-0225; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-27567 OpenBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0001/

NetApp published this final advisory covering CVE-2023-27567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26242 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0002/

NetApp published this final advisory covering CVE-2023-26242; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0464 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0006/

NetApp published this interim advisory covering CVE-2023-0464; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp Manageability SDK; NetApp SMI-S Provider; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2022-3857 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0004/

NetApp published this interim advisory covering CVE-2022-3857; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3424 Linux Kernel Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0005/

NetApp published this final advisory covering CVE-2022-3424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2021-36713 jQuery Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230406-0003/

NetApp published this final advisory covering CVE-2021-36713; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup OST Plug-in (formerly AltaVault OST Plug-in); NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp Virtual Desktop Service (VDS); SnapCenter; Spot PC.

Open source
Advisory

March 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0002/

NetApp published this interim advisory covering CVE-2023-25155, CVE-2022-36021; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

Februray 2023 Linux Kernel 5.16 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0004/

NetApp published this final advisory covering CVE-2023-22995, CVE-2023-23000; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 Golang Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0009/

NetApp published this final advisory covering CVE-2022-41724, CVE-2022-41725; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - Cloud Insights Telegraf Agent; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); StorageGRID (formerly StorageGRID Webscale); Trident.

Open source
Advisory

CVE-2023-28708 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0012/

NetApp published this final advisory covering CVE-2023-28708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24532 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0011/

NetApp published this final advisory covering CVE-2023-24532; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23003 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0003/

NetApp published this final advisory covering CVE-2023-23003; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-0594 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0007/

NetApp published this final advisory covering CVE-2023-0594; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0567 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0008/

NetApp published this final advisory covering CVE-2023-0567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0461 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0006/

NetApp published this final advisory covering CVE-2023-0461; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-4645 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0001/

NetApp published this final advisory covering CVE-2022-4645; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-20251 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230331-0005/

NetApp published this final advisory covering CVE-2021-20251; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24807 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0010/

NetApp published this final advisory covering CVE-2023-24807; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24329 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0004/

NetApp published this final advisory covering CVE-2023-24329; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-23931 Cryptography Project Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0007/

NetApp published this interim advisory covering CVE-2023-23931; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Converged Systems Advisor Agent; NetApp Virtual Desktop Service (VDS); Spot PC.

Open source
Advisory

CVE-2023-0804 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0009/

NetApp published this final advisory covering CVE-2023-0804; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0767 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0008/

NetApp published this final advisory covering CVE-2023-0767; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-0361 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0005/

NetApp published this final advisory covering CVE-2023-0361; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48282 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0003/

NetApp published this final advisory covering CVE-2022-48282; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4492 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0002/

NetApp published this final advisory covering CVE-2022-4492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2022-3219 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0001/

NetApp published this interim advisory covering CVE-2022-3219; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2020-12403 Libnss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230324-0006/

NetApp published this final advisory covering CVE-2020-12403; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Cloud Backup (formerly AltaVault).

Open source
Advisory

March 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0003/

NetApp published this final advisory covering CVE-2023-0795, CVE-2023-0796, CVE-2023-0798, CVE-2023-0799; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

February 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0008/

NetApp published this final advisory covering CVE-2023-23918, CVE-2023-23919, CVE-2023-23920; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 Linux Kernel 6.0.8 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0010/

NetApp published this final advisory covering CVE-2023-26544, CVE-2023-26606, CVE-2023-26605, CVE-2023-26607; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

February 2023 LibTIFF Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0002/

NetApp published this final advisory covering CVE-2023-0800, CVE-2023-0801, CVE-2023-0802, CVE-2023-0803; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-26545 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0009/

NetApp published this final advisory covering CVE-2023-26545; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-24580 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0006/

NetApp published this final advisory covering CVE-2023-24580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0751 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0004/

NetApp published this final advisory covering CVE-2023-0751; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0001/

NetApp published this final advisory covering CVE-2023-0240; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-47629 Libksba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0011/

NetApp published this final advisory covering CVE-2022-47629; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2006-20001 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230316-0005/

NetApp published this final advisory covering CVE-2006-20001; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

March 2023 Trusted Platform Module 2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230314-0001/

NetApp published this final advisory covering CVE-2023-1017, CVE-2023-1018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 cURL/libcURL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0006/

NetApp published this interim advisory covering CVE-2023-23914, CVE-2023-23915, CVE-2023-23916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9 (formerly Clustered Data ONTAP).

Open source
Advisory

CVE-2023-25136 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0003/

NetApp published this final advisory covering CVE-2023-25136; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-22474 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0005/

NetApp published this final advisory covering CVE-2023-22474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-47015 MariaDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0009/

NetApp published this final advisory covering CVE-2022-47015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-4139 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0004/

NetApp published this final advisory covering CVE-2022-4139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-39324 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0010/

NetApp published this final advisory covering CVE-2022-39324; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-37708 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0008/

NetApp published this final advisory covering CVE-2022-37708; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23498 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0007/

NetApp published this final advisory covering CVE-2022-23498; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-1000802 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230309-0002/

NetApp published this final advisory covering CVE-2018-1000802; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2023 Redis Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0006/

NetApp published this interim advisory covering CVE-2022-35977, CVE-2023-22458; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

January 2023 Linux Kernel 6.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0005/

NetApp published this interim advisory covering CVE-2023-0266, CVE-2023-0394; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C.

Open source
Advisory

Intel SA-00717 BIOS Firmware Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0011/

NetApp published this interim advisory covering CVE-2022-26343, CVE-2022-30539, CVE-2022-32231, CVE-2022-26837, CVE-2022-30704, CVE-2021-0187; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

February 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0009/

NetApp published this final advisory covering CVE-2022-43927, CVE-2022-43929, CVE-2022-43930; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-25139 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0010/

NetApp published this final advisory covering CVE-2023-25139; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-24998 Apache Commons FileUpload Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0013/

NetApp published this interim advisory covering CVE-2023-24998; the API labels exploitation information as **Public**. The API currently lists affected products as: 7-Mode Transition Tool; Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter; Snap Creator Framework.

Open source
Advisory

CVE-2023-23969 Django Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0007/

NetApp published this final advisory covering CVE-2023-23969; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-23559 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0003/

NetApp published this final advisory covering CVE-2023-23559; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2023-22602 Apache Shiro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0001/

NetApp published this final advisory covering CVE-2023-22602; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0122 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0002/

NetApp published this final advisory covering CVE-2023-0122; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C.

Open source
Advisory

CVE-2022-48281 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0004/

NetApp published this final advisory covering CVE-2022-48281; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-33972 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0012/

NetApp published this interim advisory covering CVE-2022-33972; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23552 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230302-0008/

NetApp published this interim advisory covering CVE-2022-23552; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2022 Net-SNMP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20230223-0011/

NetApp published this interim advisory covering CVE-2022-44792, CVE-2022-44793; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp SMI-S Provider.

Open source