Netapp Security Vulnerabilities (CVEs)

Track 348 security vulnerabilities affecting Netapp products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

66 Critical
258 High
22 Medium
2 Low
🔔 Get Alerts for Netapp
CVE-2023-45745 7.9

This vulnerability in Intel TDX module software allows a privileged user on a local system to potentially escalate privileges due to improper input va...

May 16, 2024
CVE-2024-26306 5.9

This vulnerability in iPerf3 allows attackers to exploit a timing side channel in RSA decryption operations when using OpenSSL with RSA authentication...

May 14, 2024
CVE-2024-33599 8.1

A stack-based buffer overflow vulnerability in nscd (Name Service Cache Daemon) allows attackers to execute arbitrary code or crash the service when n...

May 6, 2024
CVE-2024-33601 7.3

A memory allocation failure in nscd's netgroup cache can cause the daemon to terminate, resulting in denial of service for clients relying on name ser...

May 6, 2024
CVE-2024-25047 8.6

IBM Cognos Analytics versions 11.2.0-11.2.4 and 12.0.0-12.0.2 have improper input validation in application logging, allowing injection attacks. This ...

May 2, 2024
CVE-2024-21989 8.1

This vulnerability in ONTAP Select Deploy administration utility allows read-only users to escalate their privileges to higher administrative levels. ...

Apr 17, 2024
CVE-2024-32487 8.6

CVE-2024-32487 is a command injection vulnerability in the 'less' pager utility that allows attackers to execute arbitrary OS commands via specially c...

Apr 13, 2024
CVE-2023-29483 7.0

This vulnerability allows remote attackers to interfere with DNS name resolution by sending invalid packets from expected IP addresses and source port...

Apr 11, 2024
CVE-2023-38709 7.3

CVE-2023-38709 is an input validation vulnerability in Apache HTTP Server that allows malicious backend applications or content generators to split HT...

Apr 4, 2024
CVE-2024-27316 7.5

This vulnerability in nghttp2's HTTP/2 implementation allows memory exhaustion attacks when clients send excessive headers. Attackers can cause denial...

Apr 4, 2024
CVE-2024-2398 8.6

CVE-2024-2398 is a memory leak vulnerability in libcurl that occurs when HTTP/2 server push headers exceed the 1000-header limit. This allows attacker...

Mar 27, 2024
CVE-2024-29131 7.3

This CVE describes an out-of-bounds write vulnerability in Apache Commons Configuration that could allow attackers to write data beyond allocated memo...

Mar 21, 2024
CVE-2024-22259 8.1

Spring Framework applications using UriComponentsBuilder to parse external URLs with host validation are vulnerable to open redirect and SSRF attacks....

Mar 16, 2024
CVE-2024-28752 9.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Apache CXF's Aegis DataBinding component. It allows attackers to make unautho...

Mar 15, 2024
CVE-2024-28757 7.5

CVE-2024-28757 is an XML Entity Expansion vulnerability in libexpat that allows attackers to cause denial of service through resource exhaustion when ...

Mar 10, 2024
CVE-2024-25111 8.6

CVE-2024-25111 is an uncontrolled recursion vulnerability in Squid's HTTP chunked decoder that allows remote attackers to cause denial of service by s...

Mar 6, 2024
CVE-2024-26461 7.5

CVE-2024-26461 is a memory leak vulnerability in Kerberos 5's GSSAPI sealing implementation that can lead to denial of service through resource exhaus...

Feb 29, 2024
CVE-2023-6516 7.5

This vulnerability in BIND 9 DNS resolver allows attackers to cause uncontrolled memory growth by triggering specific query patterns that overwhelm ca...

Feb 13, 2024
CVE-2023-4408 7.5

CVE-2023-4408 is a denial-of-service vulnerability in BIND's DNS message parsing code where crafted queries cause excessive CPU consumption due to alg...

Feb 13, 2024
CVE-2023-5679 7.5

A vulnerability in BIND DNS servers where enabling both DNS64 and serve-stale features can cause named to crash during recursive resolution. This affe...

Feb 13, 2024
CVE-2024-21985 7.6

This vulnerability in NetApp ONTAP allows authenticated users with multiple remote accounts to perform REST API actions beyond their intended privileg...

Jan 26, 2024
CVE-2024-20952 7.4

This Java security vulnerability allows attackers to bypass sandbox protections in client-side Java deployments. It affects Java SE, GraalVM for JDK, ...

Jan 16, 2024
CVE-2024-20932 7.5

This vulnerability in Oracle Java SE and GraalVM allows unauthenticated attackers with network access to modify critical data in Java deployments that...

Jan 16, 2024
CVE-2024-0567 7.5

A vulnerability in GnuTLS causes Cockpit to reject certificate chains with distributed trust when using cockpit-certificate-ensure, allowing unauthent...

Jan 16, 2024
CVE-2023-23583 8.8

CVE-2023-23583 is a hardware vulnerability in certain Intel processors where specific instruction sequences can cause unexpected behavior, potentially...

Nov 14, 2023
CVE-2023-31102 7.8

This vulnerability in 7-Zip's PPMd7 compression module allows attackers to craft malicious 7Z archives that trigger an integer underflow, leading to i...

Nov 3, 2023
CVE-2023-5178 8.8

This CVE describes a use-after-free vulnerability in the NVMe/TCP subsystem of the Linux kernel that could allow attackers to execute arbitrary code o...

Nov 1, 2023
CVE-2023-46604 10.0

CVE-2023-46604 is a critical remote code execution vulnerability in Apache ActiveMQ's Java OpenWire protocol marshaller. It allows remote attackers wi...

Oct 27, 2023
CVE-2023-22102 8.3

This vulnerability in Oracle MySQL Connector/J allows an unauthenticated attacker with network access to potentially compromise the connector through ...

Oct 17, 2023
CVE-2023-27316 8.8

This vulnerability allows authenticated SnapCenter Server users to escalate privileges to admin level on remote systems where SnapCenter plug-ins are ...

Oct 12, 2023
CVE-2023-27313 8.3

This vulnerability in SnapCenter allows authenticated unprivileged users to escalate their privileges to administrative access. It affects SnapCenter ...

Oct 12, 2023
CVE-2023-44487 7.5

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server res...

Oct 10, 2023
CVE-2023-4911 7.8

CVE-2023-4911 is a buffer overflow vulnerability in the GNU C Library's dynamic loader (ld.so) that allows local attackers to exploit SUID binaries. B...

Oct 3, 2023
CVE-2023-4236 7.5

A denial-of-service vulnerability in BIND 9's DNS-over-TLS implementation causes the named service to crash when handling high volumes of DNS-over-TLS...

Sep 20, 2023
CVE-2023-1108 7.5

CVE-2023-1108 is a denial-of-service vulnerability in Undertow's SSL/TLS implementation where an infinite loop in the handshake process can crash the ...

Sep 14, 2023
CVE-2023-20900 7.1

This CVE describes a privilege escalation vulnerability in VMware vSphere where a malicious actor with Guest Operation Privileges in a target virtual ...

Aug 31, 2023
CVE-2023-41105 7.5

A vulnerability in Python 3.11 through 3.11.4 allows path truncation via null bytes in os.path.normpath(). This can bypass security checks that previo...

Aug 23, 2023
CVE-2021-32292 9.8

This is a stack buffer overflow vulnerability in json-c's auxiliary sample program json_parse. It allows attackers to execute arbitrary code or cause ...

Aug 22, 2023
CVE-2023-37920 7.5

This vulnerability affects systems using certifi Python package versions before 2023.07.22, which included compromised e-Tugra root certificates. Atta...

Jul 25, 2023
CVE-2023-32247 7.5

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to cause denial-of-service by exploiting improper resource consumption hand...

Jul 24, 2023
CVE-2023-32252 7.5

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to cause a denial-of-service by sending specially crafted SMB2_LOGOFF comma...

Jul 24, 2023
CVE-2023-32258 8.1

CVE-2023-32258 is a race condition vulnerability in the Linux kernel's ksmbd SMB server that allows local attackers to escalate privileges to kernel-l...

Jul 24, 2023
CVE-2023-38426 9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond allocated buffers when processing SMB2 create context...

Jul 18, 2023
CVE-2023-38428 9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to read memory beyond intended boundaries by exploiting improper validation...

Jul 18, 2023
CVE-2023-38430 9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to trigger an out-of-bounds read by sending specially crafted SMB requests ...

Jul 18, 2023
CVE-2023-38432 9.1

This vulnerability in the Linux kernel's ksmbd SMB server allows attackers to trigger an out-of-bounds read by sending specially crafted SMB packets w...

Jul 18, 2023
CVE-2023-32250 9.0

CVE-2023-32250 is a race condition vulnerability in the Linux kernel's ksmbd SMB server that allows attackers to execute arbitrary code with kernel pr...

Jul 10, 2023
CVE-2023-35001 7.8

This vulnerability in the Linux kernel's nftables subsystem allows local users with CAP_NET_ADMIN capability to trigger out-of-bounds read/write opera...

Jul 5, 2023
CVE-2023-3390 7.8

A use-after-free vulnerability in the Linux kernel's netfilter subsystem allows local attackers with user access to escalate privileges. The flaw occu...

Jun 28, 2023
CVE-2023-1295 7.8

A time-of-check to time-of-use (TOCTOU) vulnerability in the Linux kernel's io_uring subsystem allows a local user to escalate privileges to root. Thi...

Jun 28, 2023

Why Monitor Netapp Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 348+ known vulnerabilities affecting Netapp products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Netapp packages in under 60 seconds. No agents required - completely agentless scanning that works across Netapp deployments.

Free vulnerability database: Access detailed information about every Netapp CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Netapp CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Netapp CVEs Free