Skip to content
VulniPulse

NetApp AFF / ASA / FAS Vulnerabilities & Security Advisories

157 advisories tracked · NetApp Product Security Advisories (PSIRT) · 1 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published NetApp advisory that VulniPulse classified as AFF / ASA / FAS, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 7 critical, 49 high, 95 medium, 7 low.

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp AFF / ASA / FAS advisories

Medium5.9NetApp

Medium [CVE-2025-9232] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.5, 3.4, 3.3, 3.2 and 3.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend), NetApp HCI Baseboard Management Controller (BMC) - H610S, SnapManager for Hyper-V. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-9232
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerBlueXP / NetApp Console
Oct 3, 2025
Medium5.6NetApp

Medium [CVE-2025-9230] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.5, 3.4, 3.3, 3.2, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent Container (adc), NetApp Console Agent Container (cbs), NetApp Console Agent Container (cbs-backend), NetApp HCI Baseboard Management Controller (BMC) - H610S, ONTAP Antivirus Connector, SnapManager for Hyper-V. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-9230
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerBlueXP / NetApp Console
Oct 3, 2025
Medium4.8NetApp

Medium [CVE-2025-4373] Glib Vulnerability in NetApp Products

Multiple NetApp products incorporate glib. Glib versions prior to 2.84.2 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data or Denial of Service (DoS). Affected products: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50, Active IQ Unified Manager for VMware vSphere, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-4373
AFF / ASA / FASActive IQ Unified ManagerFAS2720
Sep 19, 2025
Medium5.9NetApp

Medium [CVE-2025-8058] Glibc Vulnerability in NetApp Products

Multiple NetApp products incorporate Glibc. Glibc versions 2.4 through 2.41 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, NetApp HCI Baseboard Management Controller (BMC) - H610S. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-8058
AFF / ASA / FASElement SoftwareFAS2720
Aug 8, 2025
Medium6.5NetApp

Medium [CVE-2025-32988] GNUTLS Vulnerability in NetApp Products

Multiple NetApp products incorporate GNUTLS. GNUTLS versions through 3.8.9 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data, Denial of Service (DoS). ONTAP Select Deploy administration utility: Affected in only 9.15.1 and 9.16.1. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time. Affected products named by the advisory: Active IQ Unified Manager for VMware vSphere; NetApp HCI Baseboard Management Controller (BMC) - H610S.

CVE-2025-32988
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Jul 25, 2025
Medium5.9NetApp

Medium [CVE-2025-26466] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions 9.5p1 through 9.9p1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). ONTAP 9: Affected only in version 9.16.1. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; and 6 more. Affected products named by the advisory: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; and 2 more.

CVE-2025-26466
ONTAPAFF / ASA / FASElement SoftwareFAS2720
Feb 28, 2025
Medium5.9NetApp

Medium [CVE-2024-13176] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), NetApp Manageability SDK, NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP tools for VMware vSphere 9, OnCommand Workflow Automation, SnapManager for Hyper-V. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2024-13176
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
Jan 24, 2025
Medium5.5NetApp

Medium [CVE-2024-26641] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-26641
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Nov 8, 2024
Medium5.5NetApp

Medium [CVE-2024-26733] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - A320, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, FAS/AFF Service Processor - A300/8200, FAS/AFF Service Processor - A700/9000, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-26733
AFF / ASA / FASSANtricityElement SoftwareFAS2720
Nov 1, 2024
Medium5.1NetApp

Medium [CVE-2024-36919] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-36919
AFF / ASA / FASElement Software
Sep 5, 2024
Medium4.4NetApp

Medium [CVE-2024-42154] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for VMware vSphere, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility, ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-42154
AFF / ASA / FASSANtricityElement SoftwareActive IQ Unified Manager
Aug 28, 2024
Medium5.6NetApp

Medium [CVE-2024-4741] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.3, 3.2, 3.1, 3.0 and 1.1.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility, OnCommand Workflow Automation, SnapManager for Hyper-V.

CVE-2024-4741
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Jun 21, 2024
Medium5.5NetApp

Medium [CVE-2023-52426] libexpat Vulnerability in NetApp Products

Multiple NetApp products incorporate libexpat. libexpat versions through 2.5.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), OnCommand Workflow Automation, SAN Host Utilities for Windows. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-52426
AFF / ASA / FASElement Software
Mar 7, 2024
Medium5.9NetApp

Medium [CVE-2023-4806] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU. GNU C Library (glibc) version 2.33 is susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-4806
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
Jan 25, 2024
Medium6.5NetApp

Medium [CVE-2023-4527] GNU C Library (glibc) Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU C. GNU C Library (glibc) versions prior to 2.39 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2023-4527
AFF / ASA / FASElement Software
Nov 16, 2023

← All NetApp advisories