Content Library · Advisory

Advisory 2024

Browse 532 2024 NetApp advisory records in the NetApp Black Box content library.

Library JSON API

Advisory

CVE-2024-49761 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0004/

NetApp published this final advisory covering CVE-2024-49761; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-48949 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0003/

NetApp published this final advisory covering CVE-2024-48949; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41123 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0005/

NetApp published this final advisory covering CVE-2024-41123; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3056 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0002/

NetApp published this final advisory covering CVE-2024-3056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52439 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0006/

NetApp published this final advisory covering CVE-2023-52439; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2018-20060 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0010/

NetApp published this interim advisory covering CVE-2018-20060; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12121 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241227-0008/

NetApp published this final advisory covering CVE-2018-12121; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

November 2024 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0008/

NetApp published this final advisory covering CVE-2024-11233, CVE-2024-11234, CVE-2024-11236; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2024-9407 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0010/

NetApp published this final advisory covering CVE-2024-9407; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-48948 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0004/

NetApp published this final advisory covering CVE-2024-48948; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45663 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0003/

NetApp published this final advisory covering CVE-2024-45663; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0002/

NetApp published this interim advisory covering CVE-2024-26882; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A1K/A70/A90; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF/ASA Baseboard Management Controller (BMC) - A20/A30/A50/C30/C60/50; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-26633 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0001/

NetApp published this final advisory covering CVE-2024-26633; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0985 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0005/

NetApp published this final advisory covering CVE-2024-0985; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-29403 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0009/

NetApp published this final advisory covering CVE-2023-29403; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-21583 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241220-0006/

NetApp published this interim advisory covering CVE-2020-21583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-9681 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0006/

NetApp published this interim advisory covering CVE-2024-9681; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-7254 Protobuf-java Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0010/

NetApp published this interim advisory covering CVE-2024-7254; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-43804 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0007/

NetApp published this interim advisory covering CVE-2023-43804; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator.

Open source
Advisory

CVE-2023-29402 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0004/

NetApp published this final advisory covering CVE-2023-29402; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29400 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0005/

NetApp published this final advisory covering CVE-2023-29400; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12123 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0008/

NetApp published this final advisory covering CVE-2018-12123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2018-12122 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0009/

NetApp published this final advisory covering CVE-2018-12122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2017-9217 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241213-0003/

NetApp published this final advisory covering CVE-2017-9217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-52533 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0009/

NetApp published this interim advisory covering CVE-2024-52533; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-39689 Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0001/

NetApp published this interim advisory covering CVE-2024-39689; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp XCP NFS; NetApp XCP SMB; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-38796 Tianocore EDK2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0006/

NetApp published this interim advisory covering CVE-2024-38796; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF BIOS - A700s; FAS/AFF BIOS - 2820; FAS/AFF BIOS - 8300/8700/A400/C400; FAS/AFF BIOS - A250/500f/C250; FAS/AFF BIOS - A300/8200/C190/A220/2720/2750/A150; FAS/AFF BIOS - A320; FAS/AFF BIOS - A700/9000; FAS/AFF BIOS - A800/C800; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2024-29857 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0008/

NetApp published this interim advisory covering CVE-2024-29857; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-28103 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0002/

NetApp published this final advisory covering CVE-2024-28103; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-42366 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0007/

NetApp published this interim advisory covering CVE-2023-42366; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-29405 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0003/

NetApp published this final advisory covering CVE-2023-29405; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-28642 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0005/

NetApp published this final advisory covering CVE-2023-28642; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-27561 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0004/

NetApp published this interim advisory covering CVE-2023-27561; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2019-12749 D-Bus Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241206-0010/

NetApp published this interim advisory covering CVE-2019-12749; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-6197 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0008/

NetApp published this final advisory covering CVE-2024-6197; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6162 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0009/

NetApp published this interim advisory covering CVE-2024-6162; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-41957 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0007/

NetApp published this interim advisory covering CVE-2024-41957; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38820 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0003/

NetApp published this interim advisory covering CVE-2024-38820; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9; SnapCenter.

Open source
Advisory

CVE-2023-6378 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0012/

NetApp published this final advisory covering CVE-2023-6378; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

CVE-2023-34042 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0010/

NetApp published this interim advisory covering CVE-2023-34042; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2023-31486 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0011/

NetApp published this interim advisory covering CVE-2023-31486; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-2610 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0006/

NetApp published this final advisory covering CVE-2023-2610; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-24539 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0005/

NetApp published this final advisory covering CVE-2023-24539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24537 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0004/

NetApp published this final advisory covering CVE-2023-24537; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48174 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0001/

NetApp published this interim advisory covering CVE-2022-48174; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-2795 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241129-0002/

NetApp published this interim advisory covering CVE-2022-2795; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

July 2024 7-Zip Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0011/

NetApp published this final advisory covering CVE-2023-52168, CVE-2023-52169; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-8373 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0003/

NetApp published this interim advisory covering CVE-2024-8373; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-8372 AngularJS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0002/

NetApp published this interim advisory covering CVE-2024-8372; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36137 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0005/

NetApp published this final advisory covering CVE-2024-36137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-30045 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0001/

NetApp published this final advisory covering CVE-2024-30045; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28835 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0009/

NetApp published this interim advisory covering CVE-2024-28835; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-22020 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0006/

NetApp published this final advisory covering CVE-2024-22020; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1459 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0008/

NetApp published this interim advisory covering CVE-2024-1459; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-1442 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0007/

NetApp published this final advisory covering CVE-2024-1442; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7008 Systemd Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0004/

NetApp published this interim advisory covering CVE-2023-7008; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2022-1304 E2fsprogs Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241122-0010/

NetApp published this interim advisory covering CVE-2022-1304; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-6384 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0001/

NetApp published this interim advisory covering CVE-2024-6384; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41965 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0002/

NetApp published this interim advisory covering CVE-2024-41965; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38428 GNU Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0005/

NetApp published this interim advisory covering CVE-2024-38428; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-29736 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0003/

NetApp published this interim advisory covering CVE-2024-29736; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-25744 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0006/

NetApp published this final advisory covering CVE-2024-25744; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-29404 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0009/

NetApp published this final advisory covering CVE-2023-29404; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24540 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0008/

NetApp published this final advisory covering CVE-2023-24540; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24538 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0007/

NetApp published this final advisory covering CVE-2023-24538; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3520 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0010/

NetApp published this interim advisory covering CVE-2022-3520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2022-0318 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241115-0004/

NetApp published this interim advisory covering CVE-2022-0318; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

June 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0002/

NetApp published this final advisory covering CVE-2022-24785, CVE-2022-31129, CVE-2010-4756, CVE-2024-21634, CVE-2024-25053, CVE-2024-25041, CVE-2024-20952, CVE-2024-20918, CVE-2024-20921, CVE-2024-20919, CVE-2024-20926, CVE-2024-20945, CVE-2023-33850, CVE-2017-20162, CVE-2023-46749, CVE-2023-5363, CVE-2017-20189, CVE-2023-44483, CVE-2018-9466, CVE-2021-36770, CVE-2023-2976, CVE-2023-22081, CVE-2023-22067, CVE-2023-5676, CVE-2021-23358, CVE-2023-24998, CVE-2021-3377, CVE-2023-26159, CVE-2022-3715, CVE-2023-37466, CVE-2023-51775, CVE-2023-37903, CVE-2023-46750, CVE-2021-20086, CVE-2023-39332, CVE-2023-38552, CVE-2023-39333, CVE-2023-39331; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

Intel SA-00999 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0003/

NetApp published this interim advisory covering CVE-2023-40067, CVE-2023-48361, CVE-2024-21844, CVE-2023-34424; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-8612 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0006/

NetApp published this final advisory covering CVE-2024-8612; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37371 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0009/

NetApp published this interim advisory covering CVE-2024-37371; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-37370 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0007/

NetApp published this interim advisory covering CVE-2024-37370; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-36138 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0010/

NetApp published this final advisory covering CVE-2024-36138; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26641 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0008/

NetApp published this final advisory covering CVE-2024-26641; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-30587 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0004/

NetApp published this final advisory covering CVE-2023-30587; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30584 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241108-0005/

NetApp published this final advisory covering CVE-2023-30584; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 PHP Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0003/

NetApp published this final advisory covering CVE-2024-8927, CVE-2024-8925, CVE-2024-8926, CVE-2024-9026; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

October 2024 MySQL Server 8.4.2 and 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0008/

NetApp published this interim advisory covering CVE-2024-21232, CVE-2024-21243, CVE-2024-21244; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

June 2023 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0011/

NetApp published this final advisory covering CVE-2023-30581, CVE-2023-30585, CVE-2023-30588, CVE-2023-30590; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-9143 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0001/

NetApp published this interim advisory covering CVE-2024-9143; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-26735 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0012/

NetApp published this interim advisory covering CVE-2024-26735; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-26733 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0013/

NetApp published this interim advisory covering CVE-2024-26733; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-23454 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0002/

NetApp published this final advisory covering CVE-2024-23454; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21247 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0006/

NetApp published this interim advisory covering CVE-2024-21247; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-21209 MySQL Client Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0005/

NetApp published this final advisory covering CVE-2024-21209; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21204 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0009/

NetApp published this interim advisory covering CVE-2024-21204; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-21200 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241101-0007/

NetApp published this interim advisory covering CVE-2024-21200; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; SnapCenter.

Open source
Advisory

October 2024 MySQL Server 8.0.39, 8.4.2, 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0006/

NetApp published this interim advisory covering CVE-2024-21193, CVE-2024-21194, CVE-2024-21196, CVE-2024-21197, CVE-2024-21198, CVE-2024-21199, CVE-2024-21201, CVE-2024-21203, CVE-2024-21213, CVE-2024-21218, CVE-2024-21219, CVE-2024-21230, CVE-2024-21231, CVE-2024-21236, CVE-2024-21237, CVE-2024-21239, CVE-2024-21241, CVE-2024-5535, CVE-2024-7264; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

October 2024 MySQL Enterprise Backup Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0010/

NetApp published this final advisory covering CVE-2024-5535, CVE-2024-7264; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21238 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0009/

NetApp published this interim advisory covering CVE-2024-21238; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21212 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0008/

NetApp published this interim advisory covering CVE-2024-21212; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21207 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0007/

NetApp published this interim advisory covering CVE-2024-21207; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2023-5764 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0001/

NetApp published this final advisory covering CVE-2023-5764; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4237 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0002/

NetApp published this final advisory covering CVE-2023-4237; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-32558 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0003/

NetApp published this final advisory covering CVE-2023-32558; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-25883 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241025-0004/

NetApp published this final advisory covering CVE-2022-25883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0010/

NetApp published this interim advisory covering CVE-2024-21208, CVE-2024-21210, CVE-2024-21217, CVE-2024-21235; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-7592 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0006/

NetApp published this interim advisory covering CVE-2024-7592; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-6232 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0007/

NetApp published this interim advisory covering CVE-2024-6232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-45492 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0005/

NetApp published this interim advisory covering CVE-2024-45492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-45491 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0003/

NetApp published this interim advisory covering CVE-2024-45491; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-45490 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0004/

NetApp published this interim advisory covering CVE-2024-45490; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-36886 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0002/

NetApp published this final advisory covering CVE-2024-36886; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-36883 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241018-0001/

NetApp published this interim advisory covering CVE-2024-36883; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

September 2024 CUPS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0001/

NetApp published this interim advisory covering CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

Intel SA-01071 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0009/

NetApp published this interim advisory covering CVE-2024-23599, CVE-2024-21871, CVE-2023-43626, CVE-2023-42772, CVE-2024-21829, CVE-2024-21781, CVE-2023-41833, CVE-2023-23904, CVE-2023-22351, CVE-2023-43753, CVE-2023-25546; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-8354 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0008/

NetApp published this final advisory covering CVE-2024-8354; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-8096 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0005/

NetApp published this interim advisory covering CVE-2024-8096; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-8088 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0010/

NetApp published this interim advisory covering CVE-2024-8088; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-7885 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0004/

NetApp published this interim advisory covering CVE-2024-7885; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-47850 CUPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0002/

NetApp published this final advisory covering CVE-2024-47850; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-47561 Apache Avro Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0003/

NetApp published this final advisory covering CVE-2024-47561; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-41909 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0006/

NetApp published this interim advisory covering CVE-2024-41909; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-27282 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241011-0007/

NetApp published this final advisory covering CVE-2024-27282; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6383 MongoDB Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0001/

NetApp published this interim advisory covering CVE-2024-6383; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45306 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0007/

NetApp published this interim advisory covering CVE-2024-45306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43802 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0008/

NetApp published this interim advisory covering CVE-2024-43802; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36946 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0002/

NetApp published this final advisory covering CVE-2024-36946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34158 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0003/

NetApp published this interim advisory covering CVE-2024-34158; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24791 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0004/

NetApp published this interim advisory covering CVE-2024-24791; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0006/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

August 2024 Node.js Elliptic Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20241004-0005/

NetApp published this final advisory covering CVE-2024-42459, CVE-2024-42460, CVE-2024-42461; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6923 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0003/

NetApp published this interim advisory covering CVE-2024-6923; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2024-45409 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0008/

NetApp published this final advisory covering CVE-2024-45409; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-41721 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0009/

NetApp published this final advisory covering CVE-2024-41721; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36902 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0002/

NetApp published this interim advisory covering CVE-2024-36902; the API labels exploitation information as **Public**. The API currently lists affected products as: E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34156 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0004/

NetApp published this final advisory covering CVE-2024-34156; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-34155 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0005/

NetApp published this interim advisory covering CVE-2024-34155; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-27399 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0001/

NetApp published this interim advisory covering CVE-2024-27399; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-30583 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0006/

NetApp published this final advisory covering CVE-2023-30583; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-30582 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240926-0007/

NetApp published this final advisory covering CVE-2023-30582; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

September 2024 FreeBSD ctl Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0010/

NetApp published this final advisory covering CVE-2024-45063, CVE-2024-8178, CVE-2024-42416, CVE-2024-43110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-8235 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0006/

NetApp published this interim advisory covering CVE-2024-8235; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7006 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0001/

NetApp published this final advisory covering CVE-2024-7006; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-43790 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0005/

NetApp published this interim advisory covering CVE-2024-43790; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43374 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0004/

NetApp published this interim advisory covering CVE-2024-43374; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-41928 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0009/

NetApp published this final advisory covering CVE-2024-41928; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38809 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0003/

NetApp published this interim advisory covering CVE-2024-38809; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38808 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0002/

NetApp published this interim advisory covering CVE-2024-38808; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-32668 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240920-0007/

NetApp published this final advisory covering CVE-2024-32668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-43102 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240916-0001/

NetApp published this final advisory covering CVE-2024-43102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0005/

NetApp published this final advisory covering CVE-2024-28762, CVE-2024-31880, CVE-2024-31881; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-00923 CSME Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0004/

NetApp published this interim advisory covering CVE-2023-28389, CVE-2023-32633; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2024-6119 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0001/

NetApp published this interim advisory covering CVE-2024-6119; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-36934 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0007/

NetApp published this interim advisory covering CVE-2024-36934; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36933 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0006/

NetApp published this interim advisory covering CVE-2024-36933; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-27398 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0012/

NetApp published this final advisory covering CVE-2024-27398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-26900 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0011/

NetApp published this interim advisory covering CVE-2024-26900; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52882 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0010/

NetApp published this interim advisory covering CVE-2023-52882; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52585 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0009/

NetApp published this interim advisory covering CVE-2023-52585; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-37920 Certifi Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0002/

NetApp published this interim advisory covering CVE-2023-37920; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Mediator; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2022-48655 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0008/

NetApp published this final advisory covering CVE-2022-48655; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240912-0003/

NetApp published this final advisory covering CVE-2024-37529, CVE-2024-35136, CVE-2024-35152, CVE-2024-31882; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39684 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0003/

NetApp published this final advisory covering CVE-2024-39684; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38517 RapidJSON Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0001/

NetApp published this final advisory covering CVE-2024-38517; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-36929 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0010/

NetApp published this interim advisory covering CVE-2024-36929; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36919 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0009/

NetApp published this interim advisory covering CVE-2024-36919; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36916 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0006/

NetApp published this interim advisory covering CVE-2024-36916; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-36905 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0005/

NetApp published this interim advisory covering CVE-2024-36905; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere/BlueXP Backup and Recovery for Virtual Machine.

Open source
Advisory

CVE-2024-36904 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0004/

NetApp published this interim advisory covering CVE-2024-36904; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

August 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0007/

NetApp published this final advisory covering CVE-2024-41989, CVE-2024-41990, CVE-2024-41991, CVE-2024-42005; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240905-0008/

NetApp published this final advisory covering CVE-2024-30260, CVE-2024-30261; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7264 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0008/

NetApp published this interim advisory covering CVE-2024-7264; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-4693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0007/

NetApp published this final advisory covering CVE-2024-4693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-42154 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0010/

NetApp published this interim advisory covering CVE-2024-42154; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-38372 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0009/

NetApp published this final advisory covering CVE-2024-38372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52433 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0003/

NetApp published this final advisory covering CVE-2023-52433; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45744 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0006/

NetApp published this final advisory covering CVE-2023-45744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-43491 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0005/

NetApp published this final advisory covering CVE-2023-43491; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29267 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240828-0004/

NetApp published this final advisory covering CVE-2023-29267; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7348 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0002/

NetApp published this final advisory covering CVE-2024-7348; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6874 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0004/

NetApp published this final advisory covering CVE-2024-6874; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4467 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0005/

NetApp published this final advisory covering CVE-2024-4467; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37891 urllib3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0003/

NetApp published this interim advisory covering CVE-2024-37891; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-3596 RADIUS Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0001/

NetApp published this final advisory covering CVE-2024-3596; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-3567 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0007/

NetApp published this final advisory covering CVE-2024-3567; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31870 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0006/

NetApp published this final advisory covering CVE-2024-31870; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-40146 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240822-0008/

NetApp published this final advisory covering CVE-2023-40146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-7589 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0002/

NetApp published this final advisory covering CVE-2024-7589; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6760 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0010/

NetApp published this final advisory covering CVE-2024-6760; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6759 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0009/

NetApp published this final advisory covering CVE-2024-6759; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6640 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0008/

NetApp published this final advisory covering CVE-2024-6640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6505 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0006/

NetApp published this final advisory covering CVE-2024-6505; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-37280 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0003/

NetApp published this interim advisory covering CVE-2024-37280; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34750 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0004/

NetApp published this interim advisory covering CVE-2024-34750; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-22018 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0007/

NetApp published this final advisory covering CVE-2024-22018; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52340 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240816-0005/

NetApp published this interim advisory covering CVE-2023-52340; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SnapCenter Plug-in for VMware vSphere.

Open source
Advisory

CVE-2020-15999 Freetype Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240812-0001/

NetApp published this final advisory covering CVE-2020-15999; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

July 2024 Django Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0005/

NetApp published this final advisory covering CVE-2024-38875, CVE-2024-39329, CVE-2024-39330, CVE-2024-39614; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6716 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0010/

NetApp published this final advisory covering CVE-2024-6716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-40898 Apache HTTP Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0006/

NetApp published this interim advisory covering CVE-2024-40898; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32007 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0009/

NetApp published this interim advisory covering CVE-2024-32007; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation; Snap Creator Framework.

Open source
Advisory

CVE-2024-0684 GNU Coreutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0001/

NetApp published this interim advisory covering CVE-2024-0684; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-39333 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0004/

NetApp published this final advisory covering CVE-2023-39333; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-23358 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240808-0003/

NetApp published this final advisory covering CVE-2021-23358; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41110 Docker Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240802-0001/

NetApp published this final advisory covering CVE-2024-41110; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 MySQL Server 8.0.37 and 8.4.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0001/

NetApp published this interim advisory covering CVE-2024-20996, CVE-2024-21125, CVE-2024-21127, CVE-2024-21129, CVE-2024-21130, CVE-2024-21134, CVE-2024-21142, CVE-2024-21162, CVE-2024-21163, CVE-2024-21171, CVE-2024-21173, CVE-2024-21177, CVE-2024-21179; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

July 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240801-0002/

NetApp published this interim advisory covering CVE-2024-21135, CVE-2024-21159, CVE-2024-21160, CVE-2024-21166; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-4076 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0001/

NetApp published this interim advisory covering CVE-2024-4076; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-21176 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0006/

NetApp published this interim advisory covering CVE-2024-21176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-21165 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0007/

NetApp published this interim advisory covering CVE-2024-21165; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-21157 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0008/

NetApp published this interim advisory covering CVE-2024-21157; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-21137 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0009/

NetApp published this interim advisory covering CVE-2024-21137; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2024-1975 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0002/

NetApp published this interim advisory covering CVE-2024-1975; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-1737 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0003/

NetApp published this interim advisory covering CVE-2024-1737; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-0760 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240731-0004/

NetApp published this final advisory covering CVE-2024-0760; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-5642 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0005/

NetApp published this interim advisory covering CVE-2024-5642; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-5585 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0002/

NetApp published this final advisory covering CVE-2024-5585; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-4032 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240726-0004/

NetApp published this interim advisory covering CVE-2024-4032; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

July 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0008/

NetApp published this interim advisory covering CVE-2024-21131, CVE-2024-21138, CVE-2024-21140, CVE-2024-21145, CVE-2024-21147; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-37894 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0001/

NetApp published this final advisory covering CVE-2024-37894; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21144 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0007/

NetApp published this interim advisory covering CVE-2024-21144; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation.

Open source
Advisory

CVE-2019-17626 ReportLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0006/

NetApp published this final advisory covering CVE-2019-17626; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2016-3751 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0004/

NetApp published this final advisory covering CVE-2016-3751; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2015-0973 Libpng Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0005/

NetApp published this final advisory covering CVE-2015-0973; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2014-9515 Dozer Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240719-0002/

NetApp published this final advisory covering CVE-2014-9515; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

July 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0001/

NetApp published this final advisory covering CVE-2024-36387, CVE-2024-38472, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP 9.

Open source
Advisory

CVE-2024-6409 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0003/

NetApp published this interim advisory covering CVE-2024-6409; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-5535 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0005/

NetApp published this interim advisory covering CVE-2024-5535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-39894 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240712-0004/

NetApp published this interim advisory covering CVE-2024-39894; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-4030 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0005/

NetApp published this final advisory covering CVE-2024-4030; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-37051 JetBrains IDE Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20240705-0004/

NetApp published this final advisory covering CVE-2024-37051; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32962 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0003/

NetApp published this final advisory covering CVE-2024-32962; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27309 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0002/

NetApp published this final advisory covering CVE-2024-27309; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1931 Unbound Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240705-0006/

NetApp published this final advisory covering CVE-2024-1931; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6387 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240701-0001/

NetApp published this interim advisory covering CVE-2024-6387; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2023-6240 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0002/

NetApp published this interim advisory covering CVE-2023-6240; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-36665 Protobuf.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0006/

NetApp published this final advisory covering CVE-2023-36665; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-1227 Podman Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240628-0001/

NetApp published this final advisory covering CVE-2022-1227; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

May 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0007/

NetApp published this final advisory covering CVE-2023-44981, CVE-2023-44487, CVE-2023-5072, CVE-2023-34462, CVE-2024-25047, CVE-2022-23540, CVE-2022-23541, CVE-2022-23539, CVE-2023-31484, CVE-2020-15366, CVE-2021-28363; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

February 2024 IBM Cognos Analytics Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0006/

NetApp published this final advisory covering CVE-2021-31684, CVE-2023-1370, CVE-2023-0464, CVE-2021-35550, CVE-2021-35560, CVE-2021-35586, CVE-2021-35578, CVE-2021-35564, CVE-2021-35559, CVE-2021-35556, CVE-2021-35565, CVE-2021-35588, CVE-2021-41035, CVE-2021-44906, CVE-2021-28167, CVE-2023-38359, CVE-2023-32344, CVE-2022-21299, CVE-2023-30996, CVE-2022-21496, CVE-2022-21434, CVE-2022-21443, CVE-2023-3817, CVE-2023-39410, CVE-2020-28458, CVE-2021-23445, CVE-2023-26136, CVE-2021-3572, CVE-2023-21930, CVE-2023-21967, CVE-2023-21954, CVE-2023-21939, CVE-2023-21968, CVE-2023-21937, CVE-2023-21938, CVE-2023-2597, CVE-2018-8032, CVE-2019-0227, CVE-2022-34357, CVE-2023-30588, CVE-2023-30589, CVE-2019-1547, CVE-2020-1971, CVE-2021-23839, CVE-2021-23840, CVE-2021-23841, CVE-2021-3449, CVE-2021-3711, CVE-2021-3712, CVE-2021-4160, CVE-2022-0778, CVE-2022-2097, CVE-2021-35603, CVE-2023-26115, CVE-2021-43138, CVE-2022-1471, CVE-2023-36478, CVE-2023-44487, CVE-2022-40897, CVE-2022-34169, CVE-2022-41854, CVE-2023-0215, CVE-2023-43051, CVE-2023-22049, CVE-2023-45857; the API labels exploitation information as **Public**. The API currently lists affected products as: OnCommand Insight.

Open source
Advisory

CVE-2024-4741 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0004/

NetApp published this interim advisory covering CVE-2024-4741; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4603 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0001/

NetApp published this interim advisory covering CVE-2024-4603; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-4577 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0008/

NetApp published this final advisory covering CVE-2024-4577; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-3080 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240621-0002/

NetApp published this interim advisory covering CVE-2022-3080; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

May 2024 Bouncy Castle Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0007/

NetApp published this interim advisory covering CVE-2024-34447, CVE-2024-30172; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-34069 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0004/

NetApp published this final advisory covering CVE-2024-34069; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-30171 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0008/

NetApp published this interim advisory covering CVE-2024-30171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp Console; ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-2877 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0002/

NetApp published this interim advisory covering CVE-2024-2877; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22233 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0005/

NetApp published this final advisory covering CVE-2024-22233; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1086 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0009/

NetApp published this final advisory covering CVE-2024-1086; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-52425 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0003/

NetApp published this interim advisory covering CVE-2023-52425; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2022-4967 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240614-0006/

NetApp published this final advisory covering CVE-2022-4967; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33883 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0003/

NetApp published this final advisory covering CVE-2024-33883; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-32487 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0009/

NetApp published this interim advisory covering CVE-2024-32487; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-24806 libuv Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0008/

NetApp published this final advisory covering CVE-2024-24806; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-24788 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0002/

NetApp published this final advisory covering CVE-2024-24788; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Astra Control Provisioner; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident; Trident Autosupport.

Open source
Advisory

CVE-2023-32067 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0004/

NetApp published this interim advisory covering CVE-2023-32067; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-31130 c-ares Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0005/

NetApp published this interim advisory covering CVE-2023-31130; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-23913 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0007/

NetApp published this final advisory covering CVE-2023-23913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20569 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0006/

NetApp published this interim advisory covering CVE-2023-20569; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-48624 less Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240605-0010/

NetApp published this final advisory covering CVE-2022-48624; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-34397 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0008/

NetApp published this final advisory covering CVE-2024-34397; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2961 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0002/

NetApp published this interim advisory covering CVE-2024-2961; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-28085 Util-linux Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0003/

NetApp published this interim advisory covering CVE-2024-28085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24787 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0006/

NetApp published this final advisory covering CVE-2024-24787; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2379 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0001/

NetApp published this interim advisory covering CVE-2024-2379; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6237 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0007/

NetApp published this interim advisory covering CVE-2023-6237; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-20593 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0004/

NetApp published this final advisory covering CVE-2023-20593; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20588 Debian Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240531-0005/

NetApp published this final advisory covering CVE-2023-20588; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-33602 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0012/

NetApp published this interim advisory covering CVE-2024-33602; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-33601 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0014/

NetApp published this interim advisory covering CVE-2024-33601; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33600 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0013/

NetApp published this interim advisory covering CVE-2024-33600; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-33599 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0011/

NetApp published this interim advisory covering CVE-2024-33599; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-28863 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0005/

NetApp published this final advisory covering CVE-2024-28863; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28834 GNU TLS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0004/

NetApp published this interim advisory covering CVE-2024-28834; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Converged Systems Advisor Agent; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-2660 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0007/

NetApp published this interim advisory covering CVE-2024-2660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22262 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0003/

NetApp published this final advisory covering CVE-2024-22262; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22259 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0002/

NetApp published this final advisory covering CVE-2024-22259; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-22243 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0001/

NetApp published this final advisory covering CVE-2024-22243; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-2048 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0009/

NetApp published this final advisory covering CVE-2024-2048; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2004 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0006/

NetApp published this interim advisory covering CVE-2024-2004; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-1313 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0008/

NetApp published this final advisory covering CVE-2024-1313; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-20863 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240524-0015/

NetApp published this final advisory covering CVE-2023-20863; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-28752 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0001/

NetApp published this final advisory covering CVE-2024-28752; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 10; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-25046 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0005/

NetApp published this final advisory covering CVE-2024-25046; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25030 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0006/

NetApp published this final advisory covering CVE-2024-25030; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2494 Libvirt Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0009/

NetApp published this interim advisory covering CVE-2024-2494; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-23450 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0010/

NetApp published this interim advisory covering CVE-2024-23450; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22025 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0008/

NetApp published this final advisory covering CVE-2024-22025; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22017 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0007/

NetApp published this final advisory covering CVE-2024-22017; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0003/

NetApp published this final advisory covering CVE-2024-22360, CVE-2023-52296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 IBM DB2 10.5, 11.1, and 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240517-0004/

NetApp published this final advisory covering CVE-2023-38729, CVE-2024-27254; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3096 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0010/

NetApp published this final advisory covering CVE-2024-3096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2757 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0011/

NetApp published this final advisory covering CVE-2024-2757; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26146 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0006/

NetApp published this final advisory covering CVE-2024-26146; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26144 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0013/

NetApp published this final advisory covering CVE-2024-26144; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26143 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0004/

NetApp published this final advisory covering CVE-2024-26143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26141 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0007/

NetApp published this final advisory covering CVE-2024-26141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25941 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0003/

NetApp published this final advisory covering CVE-2024-25941; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25126 Rack Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0005/

NetApp published this final advisory covering CVE-2024-25126; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24474 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0012/

NetApp published this final advisory covering CVE-2024-24474; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1874 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240510-0009/

NetApp published this final advisory covering CVE-2024-1874; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26142 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0003/

NetApp published this final advisory covering CVE-2024-26142; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2511 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0013/

NetApp published this interim advisory covering CVE-2024-2511; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-2466 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0010/

NetApp published this final advisory covering CVE-2024-2466; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2398 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0009/

NetApp published this interim advisory covering CVE-2024-2398; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-21885 X.Org X Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0004/

NetApp published this final advisory covering CVE-2024-21885; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0853 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0012/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6516 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0008/

NetApp published this final advisory covering CVE-2023-6516; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6129 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0011/

NetApp published this final advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5680 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0005/

NetApp published this interim advisory covering CVE-2023-5680; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5517 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0006/

NetApp published this final advisory covering CVE-2023-5517; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-5123 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0007/

NetApp published this final advisory covering CVE-2023-5123; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5122 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0002/

NetApp published this final advisory covering CVE-2023-5122; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-3010 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240503-0001/

NetApp published this final advisory covering CVE-2023-3010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2312 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0003/

NetApp published this final advisory covering CVE-2024-2312; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21015 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0010/

NetApp published this interim advisory covering CVE-2024-21015; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0853 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0009/

NetApp published this final advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5679 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0002/

NetApp published this interim advisory covering CVE-2023-5679; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-44487 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0007/

NetApp published this final advisory covering CVE-2023-44487; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-4408 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0001/

NetApp published this final advisory covering CVE-2023-4408; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2023-32665 Gnome Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0006/

NetApp published this interim advisory covering CVE-2023-32665; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

April 2024 MySQL Server 8.0.36 and 8.3.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0013/

NetApp published this interim advisory covering CVE-2023-6129, CVE-2024-20994, CVE-2024-20998, CVE-2024-21000, CVE-2024-21008, CVE-2024-21009, CVE-2024-21013, CVE-2024-21047, CVE-2024-21054, CVE-2024-21060, CVE-2024-21062, CVE-2024-21069, CVE-2024-21087, CVE-2024-21096, CVE-2024-21102; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 and 8.2.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0014/

NetApp published this interim advisory covering CVE-2024-20993, CVE-2024-21061; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0011/

NetApp published this interim advisory covering CVE-2024-21055, CVE-2024-21057; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

April 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0012/

NetApp published this interim advisory covering CVE-2024-21049, CVE-2024-21050, CVE-2024-21051, CVE-2024-21052, CVE-2024-21053, CVE-2024-21056; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

April 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0015/

NetApp published this final advisory covering CVE-2024-21101, CVE-2024-21102; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240426-0004/

NetApp published this interim advisory covering CVE-2023-41993, CVE-2024-21002, CVE-2024-21003, CVE-2024-21004, CVE-2024-21005, CVE-2024-21011, CVE-2024-21012, CVE-2024-21068, CVE-2024-21085, CVE-2024-21094; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

February 2024 QEMU Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0010/

NetApp published this final advisory covering CVE-2024-26327, CVE-2024-26328; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-25940 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0004/

NetApp published this final advisory covering CVE-2024-25940; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24758 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0007/

NetApp published this interim advisory covering CVE-2024-24758; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24750 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0006/

NetApp published this interim advisory covering CVE-2024-24750; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22257 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0005/

NetApp published this final advisory covering CVE-2024-22257; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-1597 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0008/

NetApp published this final advisory covering CVE-2024-1597; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-51780 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0001/

NetApp published this final advisory covering CVE-2023-51780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-45288 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0009/

NetApp published this final advisory covering CVE-2023-45288; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Provisioner; Trident; Trident Autosupport.

Open source
Advisory

CVE-2022-23086 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0002/

NetApp published this final advisory covering CVE-2022-23086; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23084 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240419-0003/

NetApp published this final advisory covering CVE-2022-23084; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26462 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0012/

NetApp published this interim advisory covering CVE-2024-26462; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26461 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0011/

NetApp published this interim advisory covering CVE-2024-26461; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2024-26458 MIT Kerberos 5 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0010/

NetApp published this interim advisory covering CVE-2024-26458; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Cloud Volumes ONTAP Mediator; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-6536 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0001/

NetApp published this final advisory covering CVE-2023-6536; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6535 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0003/

NetApp published this interim advisory covering CVE-2023-6535; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6356 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0002/

NetApp published this final advisory covering CVE-2023-6356; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2022-4289 GitLab Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0004/

NetApp published this interim advisory covering CVE-2022-4289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23092 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0009/

NetApp published this final advisory covering CVE-2022-23092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23091 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0008/

NetApp published this final advisory covering CVE-2022-23091; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23090 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0007/

NetApp published this final advisory covering CVE-2022-23090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23089 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0006/

NetApp published this final advisory covering CVE-2022-23089; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-23087 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0005/

NetApp published this final advisory covering CVE-2022-23087; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

April 2024 Apache HTTP Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240415-0013/

NetApp published this final advisory covering CVE-2024-27316, CVE-2024-24795, CVE-2023-38709; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; ONTAP 9; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-35191 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240405-0005/

NetApp published this interim advisory covering CVE-2023-35191; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

March 2024 Apache Tomcat Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0002/

NetApp published this final advisory covering CVE-2024-23672, CVE-2024-24549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-3094 XZ Utils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240402-0001/

NetApp published this final advisory covering CVE-2024-3094; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24785 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0008/

NetApp published this final advisory covering CVE-2024-24785; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24784 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0007/

NetApp published this final advisory covering CVE-2024-24784; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24783 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0005/

NetApp published this final advisory covering CVE-2024-24783; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2024-22201 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0001/

NetApp published this interim advisory covering CVE-2024-22201; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-21896 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0002/

NetApp published this final advisory covering CVE-2024-21896; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45290 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0004/

NetApp published this final advisory covering CVE-2023-45290; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-41946 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240329-0003/

NetApp published this final advisory covering CVE-2022-41946; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28757 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0001/

NetApp published this interim advisory covering CVE-2024-28757; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-21892 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0003/

NetApp published this final advisory covering CVE-2024-21892; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1635 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0007/

NetApp published this interim advisory covering CVE-2024-1635; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-6660 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0002/

NetApp published this final advisory covering CVE-2023-6660; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29153 Intel SPS Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0005/

NetApp published this interim advisory covering CVE-2023-29153; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp HCI Compute Node BIOS.

Open source
Advisory

CVE-2022-23085 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240322-0004/

NetApp published this final advisory covering CVE-2022-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

SnakeYAML 1.32 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0009/

NetApp published this interim advisory covering CVE-2022-38752, CVE-2022-41854; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

SnakeYAML 1.31 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0010/

NetApp published this interim advisory covering CVE-2022-38749, CVE-2022-38751, CVE-2022-38750, CVE-2022-25857; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-22234 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0003/

NetApp published this interim advisory covering CVE-2024-22234; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21891 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0005/

NetApp published this final advisory covering CVE-2024-21891; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21890 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0002/

NetApp published this interim advisory covering CVE-2024-21890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0232 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0007/

NetApp published this interim advisory covering CVE-2024-0232; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-42282 NPM Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0008/

NetApp published this final advisory covering CVE-2023-42282; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-25147 Apache Portable Runtime (APR) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240315-0001/

NetApp published this final advisory covering CVE-2022-25147; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

October 2023 Ingress nginx Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0012/

NetApp published this final advisory covering CVE-2023-5043, CVE-2023-5044; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 X.Org X Server 21.1.11 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0006/

NetApp published this final advisory covering CVE-2024-0408, CVE-2024-0409, CVE-2023-6816; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Tianocore EDK2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0011/

NetApp published this final advisory covering CVE-2023-45229, CVE-2023-45230, CVE-2023-45231, CVE-2023-45232, CVE-2023-45233, CVE-2023-45234, CVE-2023-45235, CVE-2023-45236, CVE-2023-45237; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0001/

NetApp published this final advisory covering CVE-2023-47141, CVE-2023-47152, CVE-2023-45193, CVE-2023-50308; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.5, 11.1, 11.5 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0003/

NetApp published this final advisory covering CVE-2023-47145, CVE-2023-47746; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 IBM DB2 10.1, 10.5, 11.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0002/

NetApp published this final advisory covering CVE-2023-27859, CVE-2023-47158, CVE-2023-47747; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-26308 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0009/

NetApp published this interim advisory covering CVE-2024-26308; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-25710 Apache Commons Compress Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0010/

NetApp published this interim advisory covering CVE-2024-25710; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); NetApp Console.

Open source
Advisory

CVE-2024-0853 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0004/

NetApp published this interim advisory covering CVE-2024-0853; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9.

Open source
Advisory

CVE-2023-52426 libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0005/

NetApp published this interim advisory covering CVE-2023-52426; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); OnCommand Workflow Automation; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2023-50868 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0008/

NetApp published this interim advisory covering CVE-2023-50868; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50387 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0007/

NetApp published this interim advisory covering CVE-2023-50387; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-4886 Ingress nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240307-0013/

NetApp published this final advisory covering CVE-2022-4886; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0001/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240229-0002/

NetApp published this final advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22667 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0008/

NetApp published this final advisory covering CVE-2024-22667; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-1048 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0007/

NetApp published this final advisory covering CVE-2024-1048; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-0831 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0005/

NetApp published this interim advisory covering CVE-2024-0831; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0565 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0002/

NetApp published this interim advisory covering CVE-2024-0565; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6779 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0006/

NetApp published this interim advisory covering CVE-2023-6779; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6683 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0001/

NetApp published this final advisory covering CVE-2023-6683; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6004 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0004/

NetApp published this interim advisory covering CVE-2023-6004; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-41056 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240223-0003/

NetApp published this final advisory covering CVE-2023-41056; the API labels exploitation information as **Public**. The API currently lists affected products as: Management Services for Element Software and NetApp HCI.

Open source
Advisory

CVE-2024-22207 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0002/

NetApp published this interim advisory covering CVE-2024-22207; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21733 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0005/

NetApp published this interim advisory covering CVE-2024-21733; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6246 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0007/

NetApp published this interim advisory covering CVE-2023-6246; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6129 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0009/

NetApp published this interim advisory covering CVE-2023-6129; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2023-49238 Gradle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0003/

NetApp published this final advisory covering CVE-2023-49238; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4001 Grub2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0006/

NetApp published this final advisory covering CVE-2023-4001; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-45047 Apache MINA SSHD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0008/

NetApp published this final advisory covering CVE-2022-45047; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-41678 Apache ActiveMQ Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0004/

NetApp published this interim advisory covering CVE-2022-41678; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; E-Series SANtricity Unified Manager and Web Services Proxy; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2020-1745 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0011/

NetApp published this final advisory covering CVE-2020-1745; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Service Level Manager; OnCommand Workflow Automation.

Open source
Advisory

CVE-2015-7501 Redhat JBoss Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240216-0010/

NetApp published this interim advisory covering CVE-2015-7501; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-23638 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0010/

NetApp published this final advisory covering CVE-2024-23638; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21312 .NET Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0008/

NetApp published this final advisory covering CVE-2024-21312; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0727 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0006/

NetApp published this interim advisory covering CVE-2024-0727; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; ONTAP 9; ONTAP Select Deploy administration utility; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-0057 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0007/

NetApp published this final advisory covering CVE-2024-0057; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7090 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0001/

NetApp published this final advisory covering CVE-2023-7090; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6693 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0004/

NetApp published this final advisory covering CVE-2023-6693; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-47039 Perl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0005/

NetApp published this final advisory covering CVE-2023-47039; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); SRA Plugin for Linux.

Open source
Advisory

CVE-2023-42465 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0002/

NetApp published this final advisory covering CVE-2023-42465; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-44528 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240208-0003/

NetApp published this final advisory covering CVE-2021-44528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 GnuTLS Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0011/

NetApp published this interim advisory covering CVE-2024-0567, CVE-2024-0553; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2023-3863 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0002/

NetApp published this interim advisory covering CVE-2023-3863; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-3776 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0003/

NetApp published this final advisory covering CVE-2023-3776; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34319 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0001/

NetApp published this final advisory covering CVE-2023-34319; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-28120 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0006/

NetApp published this final advisory covering CVE-2023-28120; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22796 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0009/

NetApp published this final advisory covering CVE-2023-22796; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22795 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0010/

NetApp published this final advisory covering CVE-2023-22795; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22794 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0008/

NetApp published this final advisory covering CVE-2023-22794; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-22792 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0007/

NetApp published this final advisory covering CVE-2023-22792; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-2002 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0004/

NetApp published this interim advisory covering CVE-2023-2002; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2021-22942 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240202-0005/

NetApp published this final advisory covering CVE-2021-22942; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 MySQL Server 8.0.35 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0003/

NetApp published this final advisory covering CVE-2023-5363, CVE-2024-20960, CVE-2024-20961, CVE-2024-20962, CVE-2024-20963, CVE-2024-20964, CVE-2024-20965, CVE-2024-20966, CVE-2024-20967, CVE-2024-20969, CVE-2024-20970, CVE-2024-20971, CVE-2024-20972, CVE-2024-20973, CVE-2024-20974, CVE-2024-20976, CVE-2024-20977, CVE-2024-20978, CVE-2024-20981, CVE-2024-20982, CVE-2024-20984, CVE-2024-20985; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Server 8.0.34 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0008/

NetApp published this final advisory covering CVE-2023-39975, CVE-2024-20968; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

January 2024 MySQL Cluster Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0005/

NetApp published this final advisory covering CVE-2023-2283, CVE-2023-28484, CVE-2023-38545, CVE-2023-39975; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 Java Platform Standard Edition Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0002/

NetApp published this interim advisory covering CVE-2024-20918, CVE-2024-20919, CVE-2024-20921, CVE-2024-20922, CVE-2024-20923, CVE-2024-20925, CVE-2024-20926, CVE-2024-20932, CVE-2024-20945, CVE-2024-20952; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Acquisition Unit (formerly Cloud Insights Acquisition Unit); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2024-20983 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0009/

NetApp published this interim advisory covering CVE-2024-20983; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-20965 MySQL Cluster Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0006/

NetApp published this final advisory covering CVE-2024-20965; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-31248 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240201-0001/

NetApp published this final advisory covering CVE-2023-31248; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

December 2023 X.Org X Server Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0003/

NetApp published this final advisory covering CVE-2023-6377, CVE-2023-6478; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 Infinispan Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0004/

NetApp published this interim advisory covering CVE-2023-5236, CVE-2023-3629, CVE-2023-5384, CVE-2023-3628; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Workflow Automation.

Open source
Advisory

CVE-2023-51767 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0006/

NetApp published this final advisory covering CVE-2023-51767; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4806 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0008/

NetApp published this interim advisory covering CVE-2023-4806; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-46672 Logstash Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0002/

NetApp published this final advisory covering CVE-2023-46672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46218 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0007/

NetApp published this interim advisory covering CVE-2023-46218; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-33202 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0001/

NetApp published this interim advisory covering CVE-2023-33202; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp Console; OnCommand Workflow Automation; SANtricity Storage Plugin for vCenter.

Open source
Advisory

CVE-2023-2861 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240125-0005/

NetApp published this interim advisory covering CVE-2023-2861; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

December 2023 PostgreSQL Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0003/

NetApp published this final advisory covering CVE-2023-5868, CVE-2023-5869, CVE-2023-5870; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

December 2023 IBM DB2 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0001/

NetApp published this final advisory covering CVE-2023-38003, CVE-2023-38727, CVE-2023-40687, CVE-2023-40692, CVE-2023-47701; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6277 LibTIFF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0002/

NetApp published this interim advisory covering CVE-2023-6277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-5528 Kubernetes Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0009/

NetApp published this final advisory covering CVE-2023-5528; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-50495 GNU Ncurses Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0008/

NetApp published this interim advisory covering CVE-2023-50495; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-50269 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0005/

NetApp published this final advisory covering CVE-2023-50269; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-49288 Squid Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0006/

NetApp published this final advisory covering CVE-2023-49288; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46219 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0007/

NetApp published this interim advisory covering CVE-2023-46219; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-21400 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0012/

NetApp published this interim advisory covering CVE-2023-21400; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-21255 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0010/

NetApp published this final advisory covering CVE-2023-21255; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-2007 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0011/

NetApp published this final advisory covering CVE-2023-2007; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2022-23633 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240119-0013/

NetApp published this final advisory covering CVE-2022-23633; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-7104 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0008/

NetApp published this interim advisory covering CVE-2023-7104; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-6534 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0007/

NetApp published this final advisory covering CVE-2023-6534; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6337 HashiCorp Vault Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0006/

NetApp published this final advisory covering CVE-2023-6337; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-46167 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0003/

NetApp published this final advisory covering CVE-2023-46167; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-45287 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0005/

NetApp published this final advisory covering CVE-2023-45287; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Trident Autosupport; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-45178 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0004/

NetApp published this final advisory covering CVE-2023-45178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-29258 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0002/

NetApp published this final advisory covering CVE-2023-29258; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-26031 Apache Hadoop Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240112-0001/

NetApp published this final advisory covering CVE-2023-26031; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

January 2024 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0005/

NetApp published this interim advisory covering CVE-2023-51384, CVE-2023-51385; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; E-Series SANtricity OS Controller Software 11.x; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2023-48795 SSH Protocol Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0004/

NetApp published this interim advisory covering CVE-2023-48795; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity OS Controller Software 11.x; Element Plug-in for vCenter Server; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; FAS/AFF Service Processor - A300/8200; FAS/AFF Service Processor - A700/9000; NetApp Converged Systems Advisor Agent; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; StorageGRID (formerly StorageGRID Webscale); Terraform Provider for ONTAP.

Open source
Advisory

CVE-2023-48706 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0001/

NetApp published this interim advisory covering CVE-2023-48706; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-40238 InsydeH2O Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0002/

NetApp published this final advisory covering CVE-2023-40238; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

AMI AptioV SA-2023009 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20240105-0003/

NetApp published this final advisory covering CVE-2023-39538, CVE-2023-39539; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source