Skip to content
VulniPulse
High7.5NetApp

High [CVE-2022-43680] libexpat Vulnerability in NetApp Products

This high-severity NetApp advisory covers CVE-2022-43680 affecting Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C.

NTAP-20221118-0007 Published Nov 18, 2022Updated by vendor Jul 30, 2026
Affected products & platforms
NetAppAFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
Open vendor advisory

Android app · Google Play

Monitor future NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Multiple NetApp products incorporate libexpat. libexpat versions through 2.4.9 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS).

Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP tools for VMware vSphere 10, OnCommand Workflow Automation, SAN Host Utilities for Windows.

NetApp states there is no workaround available at this time.

Affected versions
  • 2.4.9

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Fixed versions
  • Active IQ Unified Manager for VMware vSphere: 9.12
  • SAN Host Utilities for Windows: 8.0
  • NetApp HCI Compute Node (Bootstrap OS): 12.8
  • NetApp SolidFire & HCI Management Node: 12.8
  • NetApp SolidFire & HCI Storage Node (Element Software): 12.8
  • OnCommand Workflow Automation: 5.1.1P5
  • ONTAP tools for VMware vSphere 10: 10.4
  • ONTAP tools for VMware vSphere 10: 10.5

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Update affected NetApp products to a fixed release: Active IQ Unified Manager for VMware vSphere: 9.12, SAN Host Utilities for Windows: 8.0, NetApp HCI Compute Node (Bootstrap OS): 12.8, NetApp SolidFire & HCI Management Node: 12.8, NetApp SolidFire & HCI Storage Node (Element Software): 12.8, OnCommand Workflow Automation: 5.1.1P5, ONTAP tools for VMware vSphere 10: 10.4, ONTAP tools for VMware vSphere 10: 10.5.
  • NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
  • NetApp HCI Baseboard Management Controller (BMC) - H410C has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
  • NetApp HCI Baseboard Management Controller (BMC) - H610C has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
  • NetApp HCI Baseboard Management Controller (BMC) - H615C has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.

Official advisory · high-confidence parse· fetched 2 months ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.