Skip to content
VulniPulse

NetApp Security Advisories & CVEs

118 advisories tracked · NetApp Product Security Advisories (PSIRT) · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor NetApp CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Check if your NetApp device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in NetApp's recent advisories.

Official source

NetApp Product Security Advisories (PSIRT)

Polled through NetApp Product Security's official advisory API. It supplies the canonical NTAP advisory ID, NetApp-calculated CVSS, affected and investigating products, remediation releases, workarounds and revision dates without relying on a third-party keyword search.

Latest NetApp advisories

Critical9.1NetApp

Critical [CVE-2024-38821] Spring Security Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Security. Spring Security versions 5.7.0 through 5.7.12, 5.8.0 through 5.8.14, 6.0.0 through 6.0.12, 6.1.0 through 6.1.10, 6.2.0 through 6.2.6, and 6.3.0 through 6.3.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-38821
Unclassified
Jan 24, 2025
Critical9.8NetApp

Critical [CVE-2024-56337] Apache Tomcat Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache Tomcat. Apache Tomcat versions 11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, and 9.0.0.M1 through 9.0.97 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-56337
Element Software
Jan 3, 2025
Critical10.0NetApp

Critical [CVE-2024-52046] Apache MINA Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache MINA. Apache MINA versions 2.0 through 2.0.26, 2.1 through 2.1.9, and 2.2 through 2.2.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS). NetApp states there is no workaround available at this time.

CVE-2024-52046
Element Software
Jan 3, 2025
Critical9.1NetApp Updated

Critical [CVE-2024-38428] GNU Wget Vulnerability in NetApp Products

Multiple NetApp products incorporate GNU Wget. GNU Wget versions through 1.24.5 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Brocade Fabric Operating System Firmware, FAS/AFF Baseboard Management Controller (BMC) - A250/500f/C250, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP tools for VMware vSphere 10. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-38428
AFF / ASA / FASElement SoftwareONTAP tools for VMwareBrocade SANnav / Fabric OS
Nov 15, 2024
Critical9.1NetApp

Critical [CVE-2024-29736] Apache CXF Vulnerability in NetApp Products

Multiple NetApp products incorporate Apache CXF. Apache CXF versions prior to 4.0.5, 3.6.4, and 3.5.9 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Affected products: ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-29736
ONTAP tools for VMware
Nov 15, 2024
Critical9.1NetApp

Critical [CVE-2024-37371] MIT Kerberos 5 Vulnerability in NetApp Products

Multiple NetApp products incorporate MIT Kerberos 5. MIT Kerberos 5 (aka krb5) versions prior to 1.21.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, Management Services for Element Software and NetApp HCI, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, ONTAP Select Deploy administration utility, ONTAP tools for VMware vSphere 9. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-37371
AFF / ASA / FASElement SoftwareActive IQ Unified ManagerONTAP tools for VMware
Nov 8, 2024
Critical9.8NetApp

Critical [CVE-2024-45492] Libexpat Vulnerability in NetApp Products

Multiple NetApp products incorporate libexpat. libexpat versions prior to 2.6.3 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H410C, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), SAN Host Utilities for Windows. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-45492
AFF / ASA / FASElement SoftwareActive IQ Unified Manager
Oct 18, 2024
Critical9.8NetApp

Critical [CVE-2024-24790] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. Golang versions prior to go1.21.11 and go1.22.0-0 prior to go1.22.4 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Astra Control Center. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-24790
Trident / Astra
Sep 5, 2024
Critical9.9NetApp

Critical [CVE-2024-41110] Docker Vulnerability in NetApp Products

Multiple NetApp products incorporate Docker. Docker Engine versions through v19.03.15, through v20.10.27, through v23.0.14, through v24.0.9, through v25.0.5, through v26.0.2, through v26.1.4, through v27.0.3 and through v27.1.0 are susceptible to a vulnerability when authorization plugins are used to make access control decisions which when successfully exploited could lead to disclosure of information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-41110
Unclassified
Aug 2, 2024
Critical9.8NetApp

Critical [CVE-2024-33883] Node.js Vulnerability in NetApp Products

Multiple NetApp products incorporate Node.js. Node.js Embedded JavaScript templates (ejs) package versions prior to 3.1.10 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2024-33883
Unclassified
Jun 5, 2024
Critical10.0NetApp

Critical [CVE-2024-22243] Spring Framework Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Framework. Spring Framework versions 6.1.0 through 6.1.3, 6.0.0 through 6.0.16, 5.3.0 through 5.3.31 and older unsupported versions are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-22243
Active IQ Unified Manager
May 24, 2024
Critical10.0NetApp

Critical [CVE-2024-22259] Spring Framework Vulnerability in NetApp Products

Multiple NetApp products incorporate Spring Framework. Spring Framework versions 6.1.0 prior to 6.1.5, 6.0.0 prior to 6.0.18, 5.3.0 prior to 5.3.33 and older unsupported versions are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. Successful exploitation of these vulnerabilities could lead to disclosure of sensitive information or addition or modification of data. Affected products: Active IQ Unified Manager for Linux, Active IQ Unified Manager for Microsoft Windows, Active IQ Unified Manager for VMware vSphere. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-22259
Active IQ Unified Manager
May 24, 2024
Critical10.0NetApp

Critical [CVE-2024-3094] XZ Utils Vulnerability in NetApp Products

Multiple NetApp products incorporate XZ Utils. XZ Utils versions 5.6.0 and 5.6.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2024-3094
Unclassified
Apr 2, 2024
Critical10.0NetApp

Critical [CVE-2024-24785] Golang Vulnerability in NetApp Products

Multiple NetApp products incorporate Golang. html/template (a golang package) versions prior to 1.21.8 and 1.22.0 prior to 1.22.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2024-24785
Unclassified
Mar 29, 2024
Critical9.8NetApp

Critical [CVE-2024-0057] .NET Vulnerability in NetApp Products

Multiple NetApp products incorporate.NET Framework..NET versions 6.0.0 prior to 6.0.26, 7.0.0 prior to 7.0.15 and 8.0.0 prior to 8.0.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp states there is no workaround available at this time.

CVE-2024-0057
Unclassified
Feb 8, 2024
Critical9.8NetApp

Critical [CVE-2022-48522] Perl Vulnerability in NetApp Products

Multiple NetApp products incorporate Perl. Perl versions prior to 5.35.5 and 5.34.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp HCI Compute Node (Bootstrap OS), OnCommand Workflow Automation, SRA Plugin for Linux. NetApp states there is no workaround available at this time.

CVE-2022-48522
Element Software
Sep 15, 2023
Critical9.8NetApp

Critical [CVE-2022-40674] libexpat Vulnerability in NetApp Products

Multiple NetApp products incorporate libexpat. libexpat versions prior to 2.4.9 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S, NetApp HCI Baseboard Management Controller (BMC) - H610C, NetApp HCI Baseboard Management Controller (BMC) - H610S, NetApp HCI Baseboard Management Controller (BMC) - H615C, NetApp HCI Compute Node (Bootstrap OS), NetApp SolidFire & HCI Management Node, NetApp SolidFire & HCI Storage Node (Element Software), ONTAP 9, ONTAP Select Deploy administration utility, OnCommand Workflow Automation, SAN Host Utilities for Windows. NetApp states there is no workaround available at this time.

CVE-2022-40674
ONTAPAFF / ASA / FASElement SoftwareActive IQ Unified Manager
Oct 28, 2022
Critical9.8NetApp

Critical [CVE-2019-16905] OpenSSH Pre-Auth Integer Overflow Vulnerability in NetApp Products

Multiple NetApp products incorporate OpenSSH. OpenSSH versions 7.7 through 7.9 and 8.x before 8.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: NetApp Cloud Backup (formerly AltaVault), NetApp SolidFire Baseboard Management Controller (BMC), NetApp SteelStore Cloud Integrated Storage. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.

CVE-2019-16905
AFF / ASA / FASElement Software
Oct 24, 2019

← All vendors