NetAPP Alert
2804Warning Date
Severity Level
Warning Number
Target Sector
3 February, 2023
● High
2023-5439
All
NetApp has released security updates to address multiple vulnerabilities in the following products:
- Active IQ Unified Manager for Microsoft Windows
- Active IQ Unified Manager for VMware vSphere
- Management Services for Element Software and NetApp HCI
- NetApp HCI Compute Node (Bootstrap OS)
- NetApp SolidFire & HCI Management Node
- NetApp SolidFire & HCI Storage Node (Element Software)
- NetApp HCI Baseboard Management Controller (BMC) - H300S/H500S/H700S/H410S
- Other Net App products (please refer to the security advisories)
An attacker could exploit these vulnerabilities to achieve the following:
- Denial of Service (DoS)
- Sensitive Information Disclosure
- Addition or modification of data
The CERT team encourages users to update the affected products and review NetApp security advisory:
- https://security.netapp.com/advisory/ntap-20230203-0009/
- https://security.netapp.com/advisory/ntap-20230203-0004/
- https://security.netapp.com/advisory/ntap-20230203-0006/
- https://security.netapp.com/advisory/ntap-20230203-0001/
- https://security.netapp.com/advisory/ntap-20230203-0003/
- https://security.netapp.com/advisory/ntap-20230203-0005/