Content Library · Advisory

Advisory 2025

Browse 613 2025 NetApp advisory records in the NetApp Black Box content library. Page 5 of 6.

Library JSON API

Showing all 120 items on this page

Advisory

CVE-2024-8176 Libexpat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0009/

NetApp published this interim advisory covering CVE-2024-8176; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; SAN Host Utilities for Windows.

Open source
Advisory

CVE-2024-56171 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0010/

NetApp published this interim advisory covering CVE-2024-56171; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2024-54085 AMI MegaRAC Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0003/

NetApp published this final advisory covering CVE-2024-54085; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; StorageGRID Baseboard Management Controller (BMC) - SG6160/SGF6112/SG110/SG1100.

Open source
Advisory

CVE-2024-43484 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0007/

NetApp published this final advisory covering CVE-2024-43484; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-20672 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0006/

NetApp published this final advisory covering CVE-2024-20672; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-24531 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0005/

NetApp published this final advisory covering CVE-2023-24531; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Trident; Trident Autosupport.

Open source
Advisory

CVE-2021-3773 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250328-0004/

NetApp published this final advisory covering CVE-2021-3773; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 Node.js Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0003/

NetApp published this final advisory covering CVE-2025-23084, CVE-2025-23085; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24928 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0006/

NetApp published this interim advisory covering CVE-2025-24928; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; ONTAP 9.

Open source
Advisory

CVE-2025-1215 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0005/

NetApp published this final advisory covering CVE-2025-1215; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-35896 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0004/

NetApp published this interim advisory covering CVE-2024-35896; the API labels exploitation information as **Public**. The API currently lists affected products as: FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2024-35894 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0002/

NetApp published this final advisory covering CVE-2024-35894; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-2408 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0008/

NetApp published this final advisory covering CVE-2024-2408; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10524 Wget Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0007/

NetApp published this interim advisory covering CVE-2024-10524; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node.

Open source
Advisory

CVE-2021-4207 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0009/

NetApp published this final advisory covering CVE-2021-4207; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-4206 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250321-0010/

NetApp published this final advisory covering CVE-2021-4206; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-25293 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0008/

NetApp published this final advisory covering CVE-2025-25293; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-25292 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0009/

NetApp published this final advisory covering CVE-2025-25292; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-25291 Ruby SAML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0010/

NetApp published this final advisory covering CVE-2025-25291; the API labels exploitation information as **Public**. The API currently lists affected products as: StorageGRID (formerly StorageGRID Webscale).

Open source
Advisory

CVE-2025-24014 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0005/

NetApp published this final advisory covering CVE-2025-24014; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-22134 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0004/

NetApp published this final advisory covering CVE-2025-22134; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0938 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0002/

NetApp published this interim advisory covering CVE-2025-0938; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Management Services for Element Software and NetApp HCI; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9; ONTAP Mediator.

Open source
Advisory

CVE-2024-9264 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0007/

NetApp published this final advisory covering CVE-2024-9264; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-3220 Python Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250314-0001/

NetApp published this interim advisory covering CVE-2024-3220; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-27113 Libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0004/

NetApp published this interim advisory covering CVE-2025-27113; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP 9.

Open source
Advisory

CVE-2025-26603 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0003/

NetApp published this final advisory covering CVE-2025-26603; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0725 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0009/

NetApp published this interim advisory covering CVE-2025-0725; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2025-0665 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0007/

NetApp published this final advisory covering CVE-2025-0665; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0167 Libcurl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0008/

NetApp published this interim advisory covering CVE-2025-0167; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-9823 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0006/

NetApp published this interim advisory covering CVE-2024-9823; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-6763 Eclipse Jetty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0005/

NetApp published this interim advisory covering CVE-2024-6763; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2024-54133 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0010/

NetApp published this final advisory covering CVE-2024-54133; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-35176 Ruby REXML Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0001/

NetApp published this interim advisory covering CVE-2024-35176; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-1298 Tianocore EDK Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250306-0002/

NetApp published this final advisory covering CVE-2024-1298; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-26466 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0002/

NetApp published this interim advisory covering CVE-2025-26466; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; FAS/AFF Baseboard Management Controller (BMC) - FAS2820; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9.

Open source
Advisory

CVE-2025-26465 OpenSSH Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0003/

NetApp published this interim advisory covering CVE-2025-26465; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23083 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0008/

NetApp published this final advisory covering CVE-2025-23083; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0395 glibc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0006/

NetApp published this interim advisory covering CVE-2025-0395; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-40896 libxml2 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0004/

NetApp published this interim advisory covering CVE-2024-40896; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software).

Open source
Advisory

CVE-2024-26306 iperf3 Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0007/

NetApp published this final advisory covering CVE-2024-26306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-34188 Mongoose Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0001/

NetApp published this final advisory covering CVE-2023-34188; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2021-3929 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0010/

NetApp published this final advisory covering CVE-2021-3929; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3735 QEMU Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0009/

NetApp published this final advisory covering CVE-2021-3735; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3549 GNU Binutils Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250228-0005/

NetApp published this interim advisory covering CVE-2021-3549; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-25193 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0006/

NetApp published this interim advisory covering CVE-2025-25193; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-24970 Apache Netty Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0005/

NetApp published this interim advisory covering CVE-2025-24970; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight.

Open source
Advisory

CVE-2025-22866 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0002/

NetApp published this final advisory covering CVE-2025-22866; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-1094 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0010/

NetApp published this final advisory covering CVE-2025-1094; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2025-0306 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0009/

NetApp published this final advisory covering CVE-2025-0306; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-45341 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0004/

NetApp published this final advisory covering CVE-2024-45341; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator.

Open source
Advisory

CVE-2024-45338 golang.org/x/net Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0001/

NetApp published this interim advisory covering CVE-2024-45338; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45336 Golang Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0003/

NetApp published this final advisory covering CVE-2024-45336; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center - NetApp Kubernetes Monitoring Operator; Data Infrastructure Insights Telegraf Agent (formerly Cloud Insights Telegraf Agent); NetApp Kubernetes Monitoring Operator; Trident.

Open source
Advisory

CVE-2024-45310 runc Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0008/

NetApp published this interim advisory covering CVE-2024-45310; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-43709 Elasticsearch Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250221-0007/

NetApp published this final advisory covering CVE-2024-43709; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24860 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0005/

NetApp published this final advisory covering CVE-2025-24860; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-24814 Apache Solr Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0002/

NetApp published this final advisory covering CVE-2025-24814; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-23184 Apache CXF Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0003/

NetApp published this interim advisory covering CVE-2025-23184; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; ONTAP tools for VMware vSphere 9.

Open source
Advisory

CVE-2025-23015 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0006/

NetApp published this final advisory covering CVE-2025-23015; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-27137 Apache Cassandra Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0004/

NetApp published this final advisory covering CVE-2024-27137; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12797 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0001/

NetApp published this interim advisory covering CVE-2024-12797; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade Fabric Operating System Firmware; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11477 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0007/

NetApp published this final advisory covering CVE-2024-11477; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Trident Autosupport.

Open source
Advisory

CVE-2023-6918 libssh Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0009/

NetApp published this interim advisory covering CVE-2023-6918; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-6152 Grafana Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0008/

NetApp published this final advisory covering CVE-2023-6152; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-38037 Ruby on Rails Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250214-0010/

NetApp published this final advisory covering CVE-2023-38037; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

October 2024 FreeBSD Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0008/

NetApp published this final advisory covering CVE-2024-51562, CVE-2024-51563, CVE-2024-51564, CVE-2024-51565, CVE-2024-51566; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

June 2021 SELinux Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0004/

NetApp published this interim advisory covering CVE-2021-36084, CVE-2021-36085, CVE-2021-36086, CVE-2021-36087; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2025-0662 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0006/

NetApp published this final advisory covering CVE-2025-0662; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0411 7-Zip Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0005/

NetApp published this final advisory covering CVE-2025-0411; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows.

Open source
Advisory

CVE-2025-0374 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0007/

NetApp published this final advisory covering CVE-2025-0374; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2025-0373 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0009/

NetApp published this final advisory covering CVE-2025-0373; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-12705 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0003/

NetApp published this final advisory covering CVE-2024-12705; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-11187 ISC BIND Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0002/

NetApp published this interim advisory covering CVE-2024-11187; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-6780 GNU C Library (glibc) Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0010/

NetApp published this interim advisory covering CVE-2023-6780; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2023-4639 Undertow Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250207-0001/

NetApp published this interim advisory covering CVE-2023-4639; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 rsync Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0002/

NetApp published this interim advisory covering CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, CVE-2024-12747; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

January 2025 MySQL 8.0.40, 8.4.3, and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0004/

NetApp published this interim advisory covering CVE-2024-11053, CVE-2025-21500, CVE-2025-21501, CVE-2025-21518, CVE-2025-21522, CVE-2025-21497, CVE-2025-21555, CVE-2025-21559, CVE-2025-21540, CVE-2025-21490, CVE-2025-21491, CVE-2025-21503, CVE-2025-21523, CVE-2025-21531, CVE-2025-21505, CVE-2025-21529, CVE-2025-21543, CVE-2025-21519, CVE-2025-21546, CVE-2025-21520; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2024-52318 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0009/

NetApp published this final advisory covering CVE-2024-52318; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-49766 Werkzeug Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0005/

NetApp published this final advisory covering CVE-2024-49766; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-47554 Apache Commons IO Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0010/

NetApp published this interim advisory covering CVE-2024-47554; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; E-Series SANtricity Unified Manager and Web Services Proxy; NetApp BlueXP; ONTAP tools for VMware vSphere 10; ONTAP tools for VMware vSphere 9; SANtricity Storage Plugin for vCenter; SnapCenter.

Open source
Advisory

CVE-2024-45337 golang.org/x/crypto Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0007/

NetApp published this interim advisory covering CVE-2024-45337; the API labels exploitation information as **Public**. The API currently lists affected products as: Astra Control Center; Data Infrastructure Insights Telegraf Agent; NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-31141 Apache Kafka Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0001/

NetApp published this final advisory covering CVE-2024-31141; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-24789 Golang Go Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0008/

NetApp published this final advisory covering CVE-2024-24789; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-11053 curl Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250131-0003/

NetApp published this interim advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); ONTAP 9; ONTAP Select Deploy administration utility.

Open source
Advisory

January 2025 MySQL 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0014/

NetApp published this interim advisory covering CVE-2025-21566, CVE-2025-21567; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.4.3 and 9.1.0 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0013/

NetApp published this interim advisory covering CVE-2025-21499, CVE-2025-21493; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

January 2025 MySQL 8.0.39, 8.4.2, and 9.0.1 Vulnerabilities in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0010/

NetApp published this interim advisory covering CVE-2024-37371, CVE-2025-21521, CVE-2025-21525, CVE-2025-21504, CVE-2025-21536, CVE-2025-21534, CVE-2025-21494; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; NetApp BlueXP; OnCommand Insight; OnCommand Workflow Automation; SnapCenter.

Open source
Advisory

CVE-2025-21502 Java Platform Standard Edition Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0009/

NetApp published this interim advisory covering CVE-2025-21502; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Brocade SAN Navigator (SANnav); Data Infrastructure Insights Storage Workload Security Agent (formerly Cloud Insights Storage Workload Security Agent); NetApp HCI Compute Node (Bootstrap OS); OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2025-21492 MySQL Server Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0011/

NetApp published this interim advisory covering CVE-2025-21492; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; OnCommand Insight; OnCommand Workflow Automation.

Open source
Advisory

CVE-2024-52798 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0002/

NetApp published this final advisory covering CVE-2024-52798; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52317 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0004/

NetApp published this final advisory covering CVE-2024-52317; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-52316 Apache Tomcat Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0003/

NetApp published this final advisory covering CVE-2024-52316; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45296 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0001/

NetApp published this final advisory covering CVE-2024-45296; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-38827 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0007/

NetApp published this interim advisory covering CVE-2024-38827; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-38821 Spring Security Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0006/

NetApp published this final advisory covering CVE-2024-38821; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-13176 OpenSSL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0005/

NetApp published this interim advisory covering CVE-2024-13176; the API labels exploitation information as **Public**. The API currently lists affected products as: AFF Baseboard Management Controller (BMC) - A700s; Active IQ Unified Manager for Linux; Active IQ Unified Manager for VMware vSphere; Brocade Fabric Operating System Firmware; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; Management Services for Element Software and NetApp HCI; NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Baseboard Management Controller (BMC) - H610C; NetApp HCI Baseboard Management Controller (BMC) - H610S; NetApp HCI Baseboard Management Controller (BMC) - H615C; NetApp HCI Compute Node (Bootstrap OS); NetApp Manageability SDK; NetApp SolidFire & HCI Management Node; NetApp SolidFire & HCI Storage Node (Element Software); ONTAP tools for VMware vSphere 9; OnCommand Workflow Automation; SnapManager for Hyper-V.

Open source
Advisory

CVE-2024-11053 MySQL Enterprise Backup Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250124-0012/

NetApp published this final advisory covering CVE-2024-11053; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-41946 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0007/

NetApp published this final advisory covering CVE-2024-41946; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-39908 Ruby Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0008/

NetApp published this interim advisory covering CVE-2024-39908; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2024-38807 Spring Boot Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0006/

NetApp published this interim advisory covering CVE-2024-38807; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere.

Open source
Advisory

CVE-2024-29415 Node.js Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0010/

NetApp published this final advisory covering CVE-2024-29415; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-21409 .NET Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0002/

NetApp published this final advisory covering CVE-2024-21409; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-0690 Ansible Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0001/

NetApp published this interim advisory covering CVE-2024-0690; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-52434 Linux Kernel Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0009/

NetApp published this final advisory covering CVE-2023-52434; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S; NetApp HCI Baseboard Management Controller (BMC) - H410C; NetApp HCI Compute Node (Bootstrap OS); ONTAP Select Deploy administration utility; ONTAP tools for VMware vSphere 10.

Open source
Advisory

CVE-2023-41913 strongSwan Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0003/

NetApp published this final advisory covering CVE-2023-41913; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2023-0049 Vim Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0005/

NetApp published this final advisory covering CVE-2023-0049; the API labels exploitation information as **Public**. The API currently lists affected products as: NetApp HCI Compute Node (Bootstrap OS).

Open source
Advisory

CVE-2021-3918 Json-schema Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250117-0004/

NetApp published this final advisory covering CVE-2021-3918; the API labels exploitation information as **Public**. The API currently lists affected products as: Active IQ Unified Manager for Linux; Active IQ Unified Manager for Microsoft Windows; Active IQ Unified Manager for VMware vSphere; Astra Control Center.

Open source
Advisory

CVE-2024-8929 PHP Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0008/

NetApp published this final advisory covering CVE-2024-8929; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-45289 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0001/

NetApp published this final advisory covering CVE-2024-45289; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-39281 FreeBSD Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0002/

NetApp published this final advisory covering CVE-2024-39281; the API labels exploitation information as **Public**. The API did not yet publish an affected-product list, so this record should not be read as confirmation that ONTAP is affected; recheck the official advisory as the interim analysis changes.

Open source
Advisory

CVE-2024-10979 PostgreSQL Vulnerability in NetApp Products

Source: https://security.netapp.com/advisory/NTAP-20250110-0003/

NetApp published this final advisory covering CVE-2024-10979; the API labels exploitation information as **Public**. The API currently lists affected products as: Brocade SAN Navigator (SANnav); ONTAP tools for VMware vSphere 10.

Open source