Ontap Tools
Vendor:
First CVE: Jun 4, 2020 · Active for 6 years
29
Total CVEs
More Total CVEs than 96% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
6.9%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Ontap Tools over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 4, 2020
6 years ago
Most Recent CVE
Apr 24, 2025
457 days ago
CVE Severity & Scoring
Ontap Tools29 CVEs
28%
55%
14%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (13.8%)
Network23 (79.3%)
Unknown0 (0.0%)
Physical1 (3.4%)
Adjacent Network1 (3.4%)
Attack Complexity
Low26 (89.7%)
High3 (10.3%)
Unknown0 (0.0%)
User Interaction
None24 (82.8%)
Unknown0 (0.0%)
Required5 (17.2%)
Privileges Required
Low4 (13.8%)
High1 (3.4%)
None24 (82.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (29 CVEs).
29 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-3156HIGH Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line arg | Jan 26, 2021 | 7.8 | 99 | YES | YES |
CVE-2024-6387HIGH A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauth | Jul 1, 2024 | 8.1 | 89 | NO | YES |
CVE-2024-6119HIGH Issue summary: Applications performing certificate name checks (e.g., TLS
clients checking server certificates) may attempt to read an invalid memory
address resulting in abnormal | Sep 3, 2024 | 7.5 | 62 | NO | NO |
CVE-2021-28165HIGH In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame. | Apr 1, 2021 | 7.5 | 54 | NO | NO |
CVE-2024-28752CRITICAL A SSRF vulnerability using the Aegis DataBinding in versions of Apache CXF before 4.0.4, 3.6.3 and 3.5.8 allows an attacker to perform SSRF style attacks on webservices that take a | Mar 15, 2024 | 9.3 | 44 | NO | YES |
CVE-2024-52533CRITICAL gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | Nov 11, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-34750HIGH Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of | Jul 3, 2024 | 7.5 | 27 | NO | NO |
CVE-2024-38286HIGH Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10 | Nov 7, 2024 | 7.5 | 26 | NO | NO |
CVE-2023-38709HIGH Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2. | Apr 4, 2024 | 7.3 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (29 CVEs).
CISA KEV
2 CVEs
6.9% of CVEs· 97th percentile
Metasploit
2 CVEs
6.9% of CVEs· 97th percentile
Nuclei
3 CVEs
10.3% of CVEs· 97th percentile
ExploitDB
3 CVEs
10.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (29 CVEs).
Media Mentions
Signals from CVEs in this product scope (29 CVEs).
Top CNAs Publishing CVEs For Ontap Tools
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9 | 9 | 6.2 | 30.5% | 1 | 2 |
| 10 | 18 | 7.2 | 7.2% | 0 | 2 |