Ontap Tools

Vendor:

First CVE: Jun 4, 2020 · Active for 6 years

29
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
6.9%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Ontap Tools over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2020
6 years ago
Most Recent CVE
Apr 24, 2025
457 days ago

CVE Severity & Scoring

Ontap Tools29 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local4 (13.8%)
Network23 (79.3%)
Unknown0 (0.0%)
Physical1 (3.4%)
Adjacent Network1 (3.4%)
Attack Complexity
Low26 (89.7%)
High3 (10.3%)
Unknown0 (0.0%)
User Interaction
None24 (82.8%)
Unknown0 (0.0%)
Required5 (17.2%)
Privileges Required
Low4 (13.8%)
High1 (3.4%)
None24 (82.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (29 CVEs).

29 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg
Jan 26, 20217.899YESYES
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth
Jul 1, 20248.189NOYES
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal
Sep 3, 20247.562NONO
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
Apr 1, 20217.554NONO
A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take a
Mar 15, 20249.344NOYES
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
Nov 11, 20249.829NONO
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of
Jul 3, 20247.527NONO
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10
Nov 7, 20247.526NONO
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.
Apr 4, 20247.326NONO

Exploit Exposure

Signals from CVEs in this product scope (29 CVEs).

CISA KEV
2 CVEs
6.9% of CVEs· 97th percentile
Metasploit
2 CVEs
6.9% of CVEs· 97th percentile
Nuclei
3 CVEs
10.3% of CVEs· 97th percentile
ExploitDB
3 CVEs
10.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (29 CVEs).

Media Mentions

Signals from CVEs in this product scope (29 CVEs).

Top CNAs Publishing CVEs For Ontap Tools

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
996.230.5%12
10187.27.2%02