Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could allow an attacker to discover cluster, node and Active IQ Unified Manager specific information via AutoSupport telemetry data that is sent even when AutoSupport has been disabled.
References
Link | Resource |
---|---|
https://security.netapp.com/advisory/ntap-20220324-0001/ | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
References | (MISC) https://security.netapp.com/advisory/ntap-20220324-0001/ - Patch, Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:9.10:-:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:9.10:-:*:*:*:windows:*:* cpe:2.3:a:netapp:active_iq_unified_manager:9.10:-:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:* |
25 Aug 2022, 18:46
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-08-25 18:15
Updated : 2024-02-04 22:51
NVD link : CVE-2022-23235
Mitre link : CVE-2022-23235
CVE.ORG link : CVE-2022-23235
JSON object : View
Products Affected
netapp
- active_iq_unified_manager
CWE