CVE-2025-9230
CVE-2025-9230: 2 tracked advisory records across NetApp. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
NetApp
2 advisories- Advisory severityHigh7.5
High [CVE-2025-9230 +6] January 2026 MySQL Server Vulnerabilities in NetApp Products
NTAP-20260123-0009Source published Source updated
This bulletin covers 7 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
Multiple NetApp products incorporate MySQL. MySQL versions 8.0.0 through 8.0.44, 8.4.0 through 8.4.7, and 9.0.0 through 9.5.0 are susceptible to a vulnerability that could allow unauthenticated, high and low privileged attackers with network access via multiple protocols to compromise MySQL Server. Refer to “Oracle Critical Patch Update Advisory - January 2026” for additional details. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, OnCommand Insight, SnapCenter.
- Affected products in this advisory
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- OnCommand Insight
- SnapCenter
- Source-reported affected versions
- 8.0.0
- 8.0.44
- 8.4.0
- 8.4.7
2 more entries in the full advisory.
- Source-reported fixed versions
- Active IQ Unified Manager for Microsoft Windows: 9.18P3
- Active IQ Unified Manager for VMware vSphere: 9.18P3
- SnapCenter: 6.2.1
- Mitigation guidance
- Update affected NetApp products to a fixed release: Active IQ Unified Manager for Microsoft Windows: 9.18P3, Active IQ Unified Manager for VMware vSphere: 9.18P3, SnapCenter: 6.2.1.
- Workarounds
- Full Support versions of SnapCenter Server allow MySQL software to be upgraded within documented constraints. Consult the product documentation for supported MySQL versions and other information related to the upgrade. <br><br> In Full Support versions of OnCommand Insight the MySQL software can be upgraded after acquiring updated OnCommand Insight binaries via technical support.
- Advisory severityMedium5.6
Medium [CVE-2025-9230] OpenSSL Vulnerability in NetApp Products
NTAP-20251003-0011Source published Source updated
Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.5, 3.4, 3.3, 3.2, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend), NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Antivirus Connector, SnapManager for Hyper-V. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround…
- Affected products in this advisory
- Active IQ Unified Manager for Linux
- Active IQ Unified Manager for VMware vSphere
- NetApp Console Agent Container (adc)
- NetApp Console Agent Container (cbs)
4 more entries in the full advisory.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- NetApp HCI Baseboard Management Controller (BMC) - H610S has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
- SnapManager for Hyper-V has no planned fix; migrate to a supported release or product and consult NetApp's end-of-support notice.
Android app · Google Play
Monitor future NetApp CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.