Ontap

Vendor:

First CVE: Mar 30, 2023 · Active for 3 years

24
Total CVEs
More Total CVEs than 95% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ontap over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2023
3 years ago
Most Recent CVE
Mar 5, 2026
141 days ago

CVE Severity & Scoring

Ontap24 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local1 (4.2%)
Network22 (91.7%)
Unknown0 (0.0%)
Physical1 (4.2%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (79.2%)
High5 (20.8%)
Unknown0 (0.0%)
User Interaction
None19 (79.2%)
Unknown0 (0.0%)
Required5 (20.8%)
Privileges Required
Low5 (20.8%)
High0 (0.0%)
None19 (79.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, th
Apr 4, 20247.575NONO
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to v
Jul 1, 20247.573NOYES
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authenticat
Jul 1, 20248.151NOYES
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users
Jul 1, 20247.543NONO
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit serve
Feb 18, 20256.833NONO
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer over
Nov 22, 20249.832NONO
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML
Feb 18, 20259.830NONO
In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there i
Mar 30, 20259.828NONO
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.
Apr 4, 20247.326NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
8.3% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Ontap

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.17.114.30.2%00
9.16.114.30.2%00
9.15.117.51.3%00
9.14.117.51.3%00
9.13.114.60.4%00
9.12.114.60.4%00
9216.816.6%03