Ontap 9
Vendor:
First CVE: Oct 29, 2022 · Active for 3 years
7
Total CVEs
More Total CVEs than 83% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
14.3%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ontap 9 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 29, 2022
3 years ago
Most Recent CVE
Dec 18, 2024
585 days ago
CVE Severity & Scoring
Ontap 97 CVEs
29%
57%
14%
All CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (71.4%)
High2 (28.6%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38475CRITICAL Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the se | Jul 1, 2024 | 9.1 | 97 | YES | YES |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2022-42915HIGH curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNEC | Oct 29, 2022 | 8.1 | 27 | NO | NO |
CVE-2024-26461HIGH Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. | Feb 29, 2024 | 7.5 | 22 | NO | NO |
CVE-2023-27535MEDIUM An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Pre | Mar 30, 2023 | 5.9 | 22 | NO | NO |
CVE-2024-53580HIGH iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | Dec 18, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-26458MEDIUM Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. | Feb 29, 2024 | 5.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
1 CVE
14.3% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
14.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Ontap 9
Top CWEs
Versions
No cataloged versions.