Ontap Select Deploy Administration Utility

Vendor:

First CVE: Nov 10, 2016 · Active for 9 years

179
Total CVEs
More Total CVEs than 100% of tracked products
19.9
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
2.2%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ontap Select Deploy Administration Utility over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2016
9 years ago
Most Recent CVE
Feb 11, 2025
532 days ago

CVE Severity & Scoring

Ontap Select Deploy Administration Utility179 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local64 (35.8%)
Network111 (62.0%)
Unknown0 (0.0%)
Physical1 (0.6%)
Adjacent Network3 (1.7%)
Attack Complexity
Low152 (84.9%)
High27 (15.1%)
Unknown0 (0.0%)
User Interaction
None121 (67.6%)
Unknown0 (0.0%)
Required58 (32.4%)
Privileges Required
Low34 (19.0%)
High7 (3.9%)
None138 (77.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (179 CVEs).

179 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature
Nov 10, 20167.095YESYES
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 3, 20209.688YESNO
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT charac
Apr 17, 20247.387NOYES
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unaut
Feb 3, 20236.571NONO
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in
Jun 1, 20217.765NOYES
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal
Sep 3, 20247.562NONO

Exploit Exposure

Signals from CVEs in this product scope (179 CVEs).

CISA KEV
4 CVEs
2.2% of CVEs· 98th percentile
Metasploit
3 CVEs
1.7% of CVEs· 97th percentile
Nuclei
3 CVEs
1.7% of CVEs· 97th percentile
ExploitDB
5 CVEs
2.8% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (179 CVEs).

Media Mentions

Signals from CVEs in this product scope (179 CVEs).

Top CNAs Publishing CVEs For Ontap Select Deploy Administration Utility

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.2.117.51.9%00
2.217.51.9%00
2.12.119.82.0%00
2.1219.82.0%00
2.117.51.9%00
2.017.51.9%00