Skip to content
VulniPulse

NetApp AFF / ASA / FAS Vulnerabilities & Security Advisories

42 advisories tracked · NetApp Product Security Advisories (PSIRT) · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as AFF / ASA / FAS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 4 critical, 12 high, 24 medium, 2 low.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp AFF / ASA / FAS advisories

Medium4.2NetApp

Medium [CVE-2025-9086] Libcurl Vulnerability in NetApp Products

Multiple NetApp products incorporate Libcurl. Libcurl versions 7.31.0 through 8.15.0 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP 9, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-9086
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Oct 31, 2025
Medium4.8NetApp

Medium [CVE-2025-4373] Glib Vulnerability in NetApp Products

Multiple NetApp products incorporate glib. Glib versions prior to 2.84.2 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50, Active IQ Unified Manager for VMware vSphere, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-4373
AFF / ASA / FASActive IQ Unified ManagerFAS2720
Sep 19, 2025
Medium5.9NetApp

Medium [CVE-2025-26466] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions 9.5p1 through 9.9p1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). ONTAP 9: Affected only in version 9.16.1. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; and 6 more. Affected products named by the advisory: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; and 2 more.

CVE-2025-26466
ONTAPAFF / ASA / FASElement SoftwareFAS2720
Feb 28, 2025
Medium5.5NetApp

Medium [CVE-2023-52426] libexpat Vulnerability in NetApp Products

Multiple NetApp products incorporate libexpat. libexpat versions through 2.5.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), OnCommand Workflow Automation, SAN Host Utilities for Windows. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-52426
AFF / ASA / FASElement Software
Mar 7, 2024

← All NetApp advisories