Content Library · Advisory

Advisory 2025

Browse 613 2025 NetApp advisory records in the NetApp Black Box content library. Page 2 of 6.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2025-9086 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0007/

NetApp published this interim advisory covering CVE-2025-9086; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-8677 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0003/

NetApp published this interim advisory covering CVE-2025-8677; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8277 Libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0010/

NetApp published this interim advisory covering CVE-2025-8277; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7545 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0005/

NetApp published this interim advisory covering CVE-2025-7545; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55754 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0011/

NetApp published this interim advisory covering CVE-2025-55754; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-40780 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0002/

NetApp published this interim advisory covering CVE-2025-40780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-40778 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0001/

NetApp published this interim advisory covering CVE-2025-40778; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-1182 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0004/

NetApp published this interim advisory covering CVE-2025-1182; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10148 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0008/

NetApp published this interim advisory covering CVE-2025-10148; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

Open source
Advisory

CVE-2023-5156 Glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251031-0009/

NetApp published this interim advisory covering CVE-2023-5156; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-9640 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0002/

NetApp published this final advisory covering CVE-2025-9640; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-47906 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0005/

NetApp published this interim advisory covering CVE-2025-47906; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Console Agent; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-31257 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0009/

NetApp published this interim advisory covering CVE-2025-31257; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27819 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0008/

NetApp published this final advisory covering CVE-2025-27819; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27818 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0007/

NetApp published this final advisory covering CVE-2025-27818; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27817 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0006/

NetApp published this final advisory covering CVE-2025-27817; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-10230 Samba Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0001/

NetApp published this final advisory covering CVE-2025-10230; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-51744 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251024-0003/

NetApp published this interim advisory covering CVE-2024-51744; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2025 OpenSSH Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0010/

NetApp published this interim advisory covering CVE-2025-61984, CVE-2025-61985; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400.

Open source
Advisory

July 2025 LuaJIT Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0013/

NetApp published this interim advisory covering CVE-2024-25176, CVE-2024-25177, CVE-2024-25178; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6170 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0002/

NetApp published this interim advisory covering CVE-2025-6170; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp Manageability SDK; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-49795 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0001/

NetApp published this interim advisory covering CVE-2025-49795; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-47273 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0007/

NetApp published this interim advisory covering CVE-2025-47273; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-6345 Pypi/Setuptools Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0006/

NetApp published this interim advisory covering CVE-2024-6345; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2022-29217 PyJWT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0005/

NetApp published this interim advisory covering CVE-2022-29217; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2022-24801 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0009/

NetApp published this final advisory covering CVE-2022-24801; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2022-21716 Twisted Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0008/

NetApp published this final advisory covering CVE-2022-21716; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-42771 Babel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0003/

NetApp published this final advisory covering CVE-2021-42771; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-24372 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0012/

NetApp published this interim advisory covering CVE-2020-24372; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2020-15890 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0011/

NetApp published this interim advisory covering CVE-2020-15890; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2019-19391 LuaJIT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251017-0014/

NetApp published this interim advisory covering CVE-2019-19391; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-7709 SQLite Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0011/

NetApp published this interim advisory covering CVE-2025-7709; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-7039 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0009/

NetApp published this interim advisory covering CVE-2025-7039; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-6197 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0003/

NetApp published this final advisory covering CVE-2025-6197; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-6023 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0002/

NetApp published this final advisory covering CVE-2025-6023; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-49844 Redis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0012/

NetApp published this interim advisory covering CVE-2025-49844; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4056 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0010/

NetApp published this final advisory covering CVE-2025-4056; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3580 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0006/

NetApp published this final advisory covering CVE-2025-3580; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3454 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0005/

NetApp published this final advisory covering CVE-2025-3454; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-6322 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0004/

NetApp published this final advisory covering CVE-2024-6322; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35200 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0008/

NetApp published this interim advisory covering CVE-2024-35200; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-34161 Nginx Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0007/

NetApp published this interim advisory covering CVE-2024-34161; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11612 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251010-0001/

NetApp published this interim advisory covering CVE-2024-11612; the API labels exploitation information as **Public**. The API currently lists affected products as: ONTAP Select Deploy administration utility.

Open source
Advisory

CVE-2025-9784 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0007/

NetApp published this interim advisory covering CVE-2025-9784; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; OnCommand Insight.

Open source
Advisory

CVE-2025-9232 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0013/

NetApp published this interim advisory covering CVE-2025-9232; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9231 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0012/

NetApp published this interim advisory covering CVE-2025-9231; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-9230 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0011/

NetApp published this interim advisory covering CVE-2025-9230; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; NetApp Console Agent Container (adc); NetApp Console Agent Container (cbs); NetApp Console Agent Container (cbs-backend); NetApp HCI Baseboard Management Controller (BMC) - H610S; ONTAP Antivirus Connector; SnapManager for Hyper-V.

Open source
Advisory

CVE-2025-8671 HTTP/2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0004/

NetApp published this final advisory covering CVE-2025-8671; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Snap Creator Framework.

Open source
Advisory

CVE-2025-55668 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0003/

NetApp published this final advisory covering CVE-2025-55668; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-55163 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0005/

NetApp published this final advisory covering CVE-2025-55163; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5115 Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0006/

NetApp published this interim advisory covering CVE-2025-5115; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-32462 Sudo Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0001/

NetApp published this interim advisory covering CVE-2025-32462; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-27427 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0009/

NetApp published this interim advisory covering CVE-2025-27427; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-6931 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0002/

NetApp published this interim advisory covering CVE-2023-6931; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - A320; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2023-50780 Apache ActiveMQ Artemis Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0010/

NetApp published this interim advisory covering CVE-2023-50780; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-39810 Busybox Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20251003-0008/

NetApp published this interim advisory covering CVE-2023-39810; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

Intel SA-01139 UEFI Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0004/

NetApp published this interim advisory covering CVE-2024-39279, CVE-2024-31157; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF BIOS - 2820; FAS/AFF BIOS - A900/9500.

Open source
Advisory

CVE-2025-22853 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0006/

NetApp published this interim advisory covering CVE-2025-22853; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21096 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0005/

NetApp published this interim advisory covering CVE-2025-21096; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20613 Intel TDX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0007/

NetApp published this interim advisory covering CVE-2025-20613; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-57360 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0001/

NetApp published this interim advisory covering CVE-2024-57360; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31155 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0003/

NetApp published this interim advisory covering CVE-2024-31155; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-22185 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250926-0010/

NetApp published this interim advisory covering CVE-2024-22185; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4373 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0009/

NetApp published this interim advisory covering CVE-2025-4373; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; Active IQ Unified Manager for VMware vSphere; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820.

Open source
Advisory

CVE-2025-36071 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0007/

NetApp published this final advisory covering CVE-2025-36071; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-36010 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0004/

NetApp published this final advisory covering CVE-2025-36010; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-3360 Glib Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0010/

NetApp published this interim advisory covering CVE-2025-3360; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware.

Open source
Advisory

CVE-2025-33143 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0008/

NetApp published this final advisory covering CVE-2025-33143; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33114 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0006/

NetApp published this final advisory covering CVE-2025-33114; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-33092 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0005/

NetApp published this final advisory covering CVE-2025-33092; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-36293 Intel SGX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0012/

NetApp published this interim advisory covering CVE-2024-36293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-31068 Intel Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0015/

NetApp published this interim advisory covering CVE-2024-31068; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-28047 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0011/

NetApp published this interim advisory covering CVE-2024-28047; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24985 Intel ACTM Module Software Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0013/

NetApp published this interim advisory covering CVE-2024-24985; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21859 Intel UEFI Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0014/

NetApp published this interim advisory covering CVE-2024-21859; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6481 Logback Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0001/

NetApp published this interim advisory covering CVE-2023-6481; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2023-45322 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0003/

NetApp published this interim advisory covering CVE-2023-45322; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; ONTAP 9.

Open source
Advisory

CVE-2021-36368 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250919-0002/

NetApp published this interim advisory covering CVE-2021-36368; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-8916 Bouncy Castle Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0011/

NetApp published this interim advisory covering CVE-2025-8916; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-54351 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0004/

NetApp published this final advisory covering CVE-2025-54351; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-54349 Iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0003/

NetApp published this final advisory covering CVE-2025-54349; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-48913 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0001/

NetApp published this interim advisory covering CVE-2025-48913; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Snap Creator Framework.

Open source
Advisory

CVE-2025-41242 Spring Framework Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0002/

NetApp published this interim advisory covering CVE-2025-41242; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Snap Creator Framework.

Open source
Advisory

CVE-2025-24305 Intel Xeon Processors Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0010/

NetApp published this interim advisory covering CVE-2025-24305; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-22392 Intel AMT Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0005/

NetApp published this interim advisory covering CVE-2025-22392; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-21090 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0009/

NetApp published this interim advisory covering CVE-2025-21090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20067 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0007/

NetApp published this interim advisory covering CVE-2025-20067; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20053 Intel Xeon Processor Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0008/

NetApp published this interim advisory covering CVE-2025-20053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-20037 Intel CSME Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250912-0006/

NetApp published this interim advisory covering CVE-2025-20037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-5244 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0005/

NetApp published this interim advisory covering CVE-2025-5244; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-4674 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0010/

NetApp published this final advisory covering CVE-2025-4674; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Astra Control Center - NetApp Kubernetes Monitoring Operator; NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2025-3198 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0004/

NetApp published this interim advisory covering CVE-2025-3198; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-30258 GnuPG Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0002/

NetApp published this interim advisory covering CVE-2025-30258; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-23419 NGINX Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0007/

NetApp published this interim advisory covering CVE-2025-23419; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-52979 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0003/

NetApp published this interim advisory covering CVE-2024-52979; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-2240 Brocade SANnav Vulnerability

Source: https://security.netapp.com/advisory/NTAP-20250904-0001/

NetApp published this final advisory covering CVE-2024-2240; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav).

Open source
Advisory

CVE-2024-12718 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250904-0008/

NetApp published this interim advisory covering CVE-2024-12718; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2025-54090 Apache Http Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0014/

NetApp published this interim advisory covering CVE-2025-54090; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-53817 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0002/

NetApp published this final advisory covering CVE-2025-53817; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-47907 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0001/

NetApp published this interim advisory covering CVE-2025-47907; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp Console Agent.

Open source
Advisory

CVE-2025-2533 IBM Db2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250829-0010/

NetApp published this final advisory covering CVE-2025-2533; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source