← Back

Netapp

netapp

2,510 CVEs • 373 products

Products (373)

Click to collapse
Toggle
Snapcenter
snapcenter
Cloud Backup
cloud_backup
Solidfire
solidfire
Snapmanager
snapmanager
Storagegrid
storagegrid
Bootstrap Os
bootstrap_os
Data Ontap
data_ontap
Ontap Tools
ontap_tools
H300s
h300s
H500s
h500s
H700s
h700s
H410s
h410s
Ontap
ontap
Fas/aff Bios
fas/aff_bios
A250 Firmware
a250_firmware
Cloud Manager
cloud_manager
Snapdrive
snapdrive
Snapprotect
snapprotect
A400 Firmware
a400_firmware
Hci
hci
8300 Firmware
8300_firmware
8700 Firmware
8700_firmware

CVEs (2,510)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Intel
Netapp
681Atom C3308 Firmware
Atom C3336 FirmwareAtom C3338 Firmware+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
681Atom C3308 Firmware
Atom C3336 FirmwareAtom C3338 Firmware+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
2Intel
Netapp
681Atom C3308
Atom C3336Atom C3338+678 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.
2Intel
Netapp
1611th Generation Core Series Firmware
Atom C3000 Series FirmwareAtom C610 Series Firmware+13 more
Jun 17, 2026
Feb 9, 2022
N/A· v4
6.6 MEDIUM· v3
7.2 HIGH· v2
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101...Show more
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0, IGN_E5_91.00.00.167.0, SPS_PHI_03.01.03.078.0 may allow an authenticated user to potentially enable escalation of privilege via physical access.Show less
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticate...Show more
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the specific team ID, `/teams/:search` will allow an authenticated attacker to search for teams and see the total number of available teams, including for those teams that the user does not have access to, and `/teams/:teamId/members` when editors_can_admin flag is enabled, an authenticated attacker can see unintended data by querying for the specific team ID. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.Show less
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin...Show more
Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users (for example, Editors or Admins). An attacker can exploit this vulnerability for privilege escalation by tricking an authenticated user into inviting the attacker as a new user with high privileges. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.Show less
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a...Show more
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set up its own public service and instruct anyone to set it up in their Grafana instance. To be impacted, all of the following must be applicable. For the data source proxy: A Grafana HTTP-based datasource configured with Server as Access Mode and a URL set, the attacker has to be in control of the HTTP server serving the URL of above datasource, and a specially crafted link pointing at the attacker controlled data source must be clicked on by an authenticated user. For the plugin proxy: A Grafana HTTP-based app plugin configured and enabled with a URL set, the attacker has to be in control of the HTTP server serving the URL of above app, and a specially crafted link pointing at the attacker controlled plugin must be clocked on by an authenticated user. For the backend plugin resource: An attacker must be able to navigate an authenticated user to a compromised plugin through a crafted link. Users are advised to update to a patched version. There are no known workarounds for this vulnerability.Show less
2Apache
Netapp
4Active Iq Unified Manager
Activemq ArtemisArtemis+1 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory.
3Linux
NetappRedhat
4Enterprise Linux
Hci Baseboard Management ControllerLinux Kernel+1 more
Jun 17, 2026
Feb 4, 2022
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsco...Show more
A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 parser. A local attacker with a user privilege could cause a privilege escalation by exploiting the fsconfig syscall parameter leading to a container breakout and a denial of service on the system.Show less
3Insyde
NetappSiemens
18Fas/aff Bios
Insydeh2oRuggedcom Ape1808 Firmware+15 more
Jun 17, 2026
Feb 3, 2022
N/A· v4
7.5 HIGH· v3
6.9 MEDIUM· v2
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the bu...Show more
An issue was discovered in Kernel 5.x in Insyde InsydeH2O, affecting HddPassword. Software SMI services that use the Communicate() function of the EFI_SMM_COMMUNICATION_PROTOCOL do not check whether the address of the buffer is valid, which allows use of SMRAM, MMIO, or OS kernel addresses.Show less
3Fedoraproject
LinuxNetapp
10Fedora
H300e FirmwareH300s Firmware+7 more
Jun 17, 2026
Jan 29, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
3Debian
LinuxNetapp
118300 Firmware
8700 FirmwareA400 Firmware+8 more
Jun 17, 2026
Jan 26, 2022
N/A· v4
7.0 HIGH· v3
7.2 HIGH· v2
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions...Show more
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755Show less
5Debian
FedoraprojectGoogle+2 more
8Active Iq Unified Manager
Debian LinuxFedora+5 more
Jun 17, 2026
Jan 26, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the sym...Show more
Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.Show less