Skip to content
VulniPulse

NetApp Security Advisories & CVEs

286 advisories tracked · NetApp Product Security Advisories (PSIRT) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetApp device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetApp's recent advisories.

Official source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp advisories

Medium6.9NetApp

Medium [CVE-2025-27533] Apache ActiveMQ Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache ActiveMQ. Apache ActiveMQ versions 6.0.0 prior to 6.1.6, 5.18.0 prior to 5.18.7, 5.17.0 prior to 5.17.7, and 5.16.0 prior to 5.16.8 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Linux. NetApp states there is no workaround available at this time.

CVE-2025-27533
Active IQ Unified Manager
Jul 4, 2025
Medium5.6NetApp Updated

Medium [CVE-2025-29088] SQLite Vulnerability in NetApp Products

Multiple NetApp products incorporate SQLite. SQLite versions 3.49.0 prior to 3.49.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-29088
Element Software
Jun 5, 2025
Medium6.9NetApp Updated

Medium [CVE-2025-3277] SQLite Vulnerability in NetApp Products

Multiple NetApp products incorporate SQLite. Certain versions of SQLite are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-3277
Element SoftwareActive IQ Unified Manager
May 30, 2025
Medium5.0NetApp

Medium [CVE-2025-1181] GNU Binutils Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU Binutils. GNU Binutils versions through 2.43 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-1181
Element Software
Apr 25, 2025
Medium6.2NetApp

Medium [CVE-2024-0450] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Certain versions of Python are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, NetApp HCI Compute Node (Bootstrap OS), ONTAP 9. NetApp states there is no workaround available at this time.

CVE-2024-0450
ONTAPElement SoftwareActive IQ Unified Manager
Apr 11, 2025
Medium5.0NetApp

Medium [CVE-2025-1176] GNU Binutils Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU Binutils. GNU Binutils version 2.43 is susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-1176
Element Software
Apr 11, 2025
Medium5.6NetApp

Medium [CVE-2025-1178] GNU Binutils Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU Binutils. GNU Binutils version 2.43 is susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-1178
Element SoftwareActive IQ Unified Manager
Apr 11, 2025
Medium5.9NetApp

Medium [CVE-2025-1153] GNU Binutils Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU Binutils. GNU Binutils versions 2.43 and 2.44 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-1153
Element SoftwareActive IQ Unified Manager
Apr 4, 2025
Medium5.6NetApp

Medium [CVE-2025-23084 +1] January 2025 Node.js Vulnerabilities in NetApp Products

Multiple NetApp products incorporate Node.js versions 18.x, 20.x, 22.x, and 23.x are susceptible to vulnerabilities which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2025-23084CVE-2025-23085
Unclassified
Mar 21, 2025
Medium5.3NetApp

Medium [CVE-2024-6763] Eclipse Jetty Vulnerability in NetApp Products

Multiple NetApp products incorporate Eclipse Jetty. Eclipse Jetty versions 7.0.0 through 12.0.11 are susceptible to a vulnerability which when successfully exploited could lead to addition or modification of data. Successful exploitation of this vulnerability could lead to addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, NetApp Console Agent, NetApp HCI Compute Node (Bootstrap OS), ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-6763
Element SoftwareActive IQ Unified ManagerBlueXP / NetApp ConsoleONTAP tools for VMware
Mar 6, 2025
Medium5.9NetApp

Medium [CVE-2025-26466] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions 9.5p1 through 9.9p1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). ONTAP 9: Affected only in version 9.16.1. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. Affected products named by the advisory: AFF Baseboard Management Controller (BMC) - A700s; AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70; AFF/ASA/FAS Baseboard Management Controller (BMC) - A50/A30/A20/C60/C30/FAS50; FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400; and 6 more. Affected products named by the advisory: FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250; FAS/AFF Baseboard Management Controller (BMC) - A800/C800; FAS/AFF Baseboard Management Controller (BMC) - A900/9500; FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750; and 2 more.

CVE-2025-26466
ONTAPAFF / ASA / FASElement SoftwareFAS2720
Feb 28, 2025
Medium6.8NetApp Updated

Medium [CVE-2025-26465] OpenSSH Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions 6.8p1 through 9.9p1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2025-26465
Element SoftwareActive IQ Unified ManagerONTAP tools for VMware
Feb 28, 2025
Medium5.9NetApp

Medium [CVE-2024-13176] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.4, 3.3, 3.2, 3.1, 3.0, 1.1.1 and 1.0.2 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information. Successful exploitation of this vulnerability could lead to disclosure of sensitive information. Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), NetApp Manageability SDK, NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP tools for VMware vSphere 9, OnCommand Workflow Automation, SnapManager for Hyper-V. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status.

CVE-2024-13176
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
Jan 24, 2025
Medium5.5NetApp

Medium [CVE-2024-26641] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-26641
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Nov 8, 2024
Medium5.5NetApp

Medium [CVE-2024-26733] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, AFF/ASA/FAS Baseboard Management Controller (BMC) - A1K/A90/A70/C80/FAS90/FAS70, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - A320, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, FAS/AFF Service Processor - A300/8200, FAS/AFF Service Processor - A700/9000, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-26733
AFF / ASA / FASSANtricityElement SoftwareFAS2720
Nov 1, 2024
Medium6.8NetApp Updated

Medium [CVE-2024-6923] Python Vulnerability in NetApp Products

Multiple NetApp products incorporate Python. Certain versions of Python (CPython) are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere, NetApp HCI Compute Node (Bootstrap OS), ONTAP 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-6923
ONTAPElement SoftwareActive IQ Unified Manager
Sep 26, 2024
Medium5.1NetApp

Medium [CVE-2024-36919] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-36919
AFF / ASA / FASElement Software
Sep 5, 2024
Medium4.4NetApp

Medium [CVE-2024-42154] Linux Kernel Vulnerability in NetApp Products

Multiple NetApp products incorporate Linux kernel. Certain versions of Linux kernel are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for VMware vSphere, E-Series SANtricity OS Controller Software, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility, ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-42154
AFF / ASA / FASSANtricityElement SoftwareActive IQ Unified Manager
Aug 28, 2024
Medium5.5NetApp

Medium [CVE-2024-3567] QEMU Vulnerability in NetApp Products

StorageGRID (formerly StorageGRID Webscale) incorporates QEMU. Certain versions of QEMU are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-3567
Unclassified
Aug 22, 2024
Medium5.6NetApp

Medium [CVE-2024-4741] OpenSSL Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSL. OpenSSL versions 3.3, 3.2, 3.1, 3.0 and 1.1.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: AFF Baseboard Management Controller (BMC) - A700s, Active IQ Unified Manager for Linux, Active IQ Unified Manager for VMware vSphere, Brocade Fabric Operating System Firmware, FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400/C400, FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250, FAS/AFF Baseboard Management Controller (BMC) - A800/C800, FAS/AFF Baseboard Management Controller (BMC) - A900/9500, FAS/AFF Baseboard Management Controller (BMC) - C190/A150/A220/FAS2720/FAS2750, FAS/AFF Baseboard Management Controller (BMC) - FAS2820, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), ONTAP Select Deploy administration utility, OnCommand Workflow Automation, SnapManager for Hyper-V.

CVE-2024-4741
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Jun 21, 2024

← All vendors