Vulnerabilities in NETAPP
69 resultsVexday analysis
NetApp apresenta 7 vulnerabilidades catalogadas, com 3 divulgações recentes (últimos 90 dias), mas nenhuma em exploração ativa conhecida e sem críticas de severidade máxima. A fraqueza predominante é CWE-259 (credenciais codificadas), indicando falhas de gestão de segredos que demandam revisão de práticas de configuração e deployment.
CVE-2023-27317MEDIUMInformation Disclosure Vulnerability in ONTAP 9 EPSS 0.4%CVE-2023-27319MEDIUM CVE-2023-27319 Information Disclosure Vulnerability in ONTAP MediatorEPSS 0.4%CVE-2018-5496—Data ONTAP operating in 7-Mode versions prior to 8.2.5P2 are susceptible to a vulnerability which discloses sensitive information to an unauEPSS 0.4%CVE-2024-21982MEDIUM CVE-2024-21982 Information Disclosure Vulnerability in ONTAP 9 EPSS 0.4%CVE-2017-15517—AltaVault OST Plug-in versions prior to 1.2.2 may allow attackers to obtain sensitive information via unspecified vectors. All users are urgEPSS 0.4%CVE-2018-5497—Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to EPSS 0.4%CVE-2025-26516MEDIUMCVE-2025-26516 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.4%CVE-2023-27312MEDIUMPrivilege Escalation Vulnerability in SnapCenter Plugin for VMware vSphere EPSS 0.4%CVE-2024-21994MEDIUMCVE-2024-21994 Denial of Service Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.3%CVE-2017-15518—All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged database user account EPSS 0.3%CVE-2024-21985HIGHPrivilege Escalation Vulnerability in ONTAP 9 EPSS 0.3%CVE-2024-21990MEDIUMDefault Privileged Account Credentials Vulnerability in ONTAP Select Deploy administration utilityEPSS 0.3%CVE-2025-26515HIGHCVE-2025-26515 Server-Side Request Forgery Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.3%CVE-2024-21984MEDIUMReflected Cross-Site Scripting Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.3%CVE-2026-22049HIGHONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to thEPSS 0.3%CVE-2024-21987MEDIUMImproper Authorization Vulnerability in SnapCenterEPSS 0.3%CVE-2026-22048HIGHStorageGRID (formerly StorageGRID Webscale) versions prior to 11.9.0.12 and 12.0.0.4 with Single Sign-on enabled and configured to use MicroEPSS 0.3%CVE-2026-22055MEDIUMActive IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to performEPSS 0.2%CVE-2026-22054MEDIUMActive IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perEPSS 0.2%CVE-2024-21988MEDIUMCVE-2024-21988 SSH Cryptographic Implementation Vulnerability in StorageGRID (formerly StorageGRID Webscale)EPSS 0.2%