NetApp, Inc.

First CVE: Nov 10, 2017Active for: 9 years
133
CVEs Published
More CVEs Published than 74% of tracked CNAs
13.3
Avg CVEs / Year
More Avg CVEs / Year than 61% of tracked CNAs
6.8
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by NetApp, Inc. as a CNA, 96.2% affect products that NetApp, Inc. develops as a vendor.

96.2%
Self-reported: 128Third-party: 5

Of all the CVEs published that affect products developed by NetApp, Inc., 5.1% are self-published by NetApp, Inc. as a CNA.

94.9%
Self-published: 128Published by other CNAs: 2,383

Trends Over Time

The number and severity of CVEs published by NetApp, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2017
8 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by NetApp, Inc. as a CNA, regardless of affected vendor or product.

133 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successful
Jul 22, 20268.736NONO
Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations
Jun 3, 20268.836NONO
Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.
Jun 3, 20268.835NONO
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command
Jul 1, 20199.832NONO
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary
Mar 21, 20199.832NONO
SnapCenter versions prior to 6.0.1P1 and 6.1P1 are susceptible to a vulnerability which may allow an authenticated SnapCenter Server user to become an admin user on a remote sys
Mar 24, 20259.931NONO
SnapCenter versions 4.7 prior to 4.7P2 and 4.8 prior to 4.8P1 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to gain access as an admin user
May 12, 20239.831NONO
NetApp Virtual Desktop Service (VDS) when used with an HTML5 gateway is susceptible to a vulnerability which when successfully exploited could allow an unauthenticated attacker to
Dec 23, 20219.831NONO
NetApp OnCommand Unified Manager for Linux versions 7.2 through 7.3 ship with the Java Management Extension Remote Method Invocation (JMX RMI) service bound to the network, and are
May 24, 20189.831NONO
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploi
Mar 15, 20219.830NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA133 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local22 (16.5%)
Network106 (79.7%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network4 (3.0%)
Attack Complexity
Low124 (93.2%)
High9 (6.8%)
Unknown0 (0.0%)
User Interaction
None123 (92.5%)
Unknown0 (0.0%)
Required10 (7.5%)
Privileges Required
Low56 (42.1%)
High10 (7.5%)
None67 (50.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (133 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by NetApp, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by NetApp, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs