Netapp
Netapp Cloud Backup: vulnerabilidades y CVE
Netapp Cloud Backup tiene 349 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 37 son críticas y 8 figuran en el catálogo de explotación activa de CISA.
CVE349
Últimos 12 meses0
Críticas37
Explotadas activamente8
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22555 | Alta (7.8) | 79% | ⚠ Explotación activa | 7 jul 2021 | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space |
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2021-3156 | Alta (7.8) | 100% | ⚠ Explotación activa | 26 ene 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash… |
| CVE-2016-5195 | Alta (7) | 84% | ⚠ Explotación activa | 10 nov 2016 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,… |
| CVE-2021-40438 | Crítica (9) | 100% | ⚠ Explotación activa | 16 sept 2021 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
| CVE-2021-41773 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 oct 2021 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If… |
| CVE-2019-2215 | Alta (7.8) | 72% | ⚠ Explotación activa | 11 oct 2019 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the… |
| CVE-2021-42013 | Crítica (9.8) | 100% | ⚠ Explotación activa | 7 oct 2021 | It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives.… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-28656 | Alta (8.1) | 0.53% | — | 3 may 2023 | NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are… |
| CVE-2021-33068 | Media (6.5) | 0.84% | — | 9 feb 2022 | Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access. |
| CVE-2021-0156 | Alta (7.8) | 0.30% | — | 9 feb 2022 | Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0125 | Media (6.6) | 0.30% | — | 9 feb 2022 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. |
| CVE-2021-0124 | Media (6.6) | 0.32% | — | 9 feb 2022 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. |
| CVE-2021-0119 | Media (6.2) | 0.30% | — | 9 feb 2022 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. |
| CVE-2021-0118 | Media (6.7) | 0.30% | — | 9 feb 2022 | Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0117 | Alta (7.8) | 0.30% | — | 9 feb 2022 | Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0116 | Alta (7.8) | 0.30% | — | 9 feb 2022 | Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0115 | Media (6.7) | 0.33% | — | 9 feb 2022 | Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2021-0111 | Media (6.7) | 0.30% | — | 9 feb 2022 | NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0107 | Media (6.7) | 0.30% | — | 9 feb 2022 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |
| CVE-2021-0103 | Media (6.7) | 0.30% | — | 9 feb 2022 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0099 | Alta (7.8) | 0.30% | — | 9 feb 2022 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0093 | Media (4.4) | 0.24% | — | 9 feb 2022 | Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. |
| CVE-2021-0092 | Media (4.4) | 0.25% | — | 9 feb 2022 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. |
| CVE-2021-0091 | Alta (7.8) | 0.33% | — | 9 feb 2022 | Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access. |
| CVE-2021-0060 | Media (6.6) | 0.32% | — | 9 feb 2022 | Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0,… |
| CVE-2021-44790 | Crítica (9.8) | 97% | — | 20 dic 2021 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might… |
| CVE-2021-4044 | Alta (7.5) | 50% | — | 14 dic 2021 | Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. That function may return a negative return value to indicate an internal error (for example out of… |
| CVE-2021-43527 | Crítica (9.8) | 18% | — | 8 dic 2021 | NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within… |
| CVE-2018-25020 | Alta (7.8) | 0.51% | — | 8 dic 2021 | The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an… |
| CVE-2021-43976 | Media (4.6) | 0.69% | — | 17 nov 2021 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). |
| CVE-2021-43975 | Media (6.7) | 0.55% | — | 17 nov 2021 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via… |
| CVE-2021-42377 | Crítica (9.8) | 3.6% | — | 15 nov 2021 | An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used… |
| CVE-2021-42376 | Media (5.5) | 0.43% | — | 15 nov 2021 | A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very… |
| CVE-2021-42375 | Media (5.5) | 0.41% | — | 15 nov 2021 | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be… |
| CVE-2021-42374 | Media (5.3) | 0.62% | — | 15 nov 2021 | An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that |
| CVE-2021-42373 | Media (5.5) | 0.41% | — | 15 nov 2021 | A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given |
| CVE-2017-5123 | Alta (8.8) | 3.7% | — | 2 nov 2021 | Insufficient data validation in waitid allowed an user to escape sandboxes on Linux. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575H700s Firmware · 293H300s Firmware · 292H410s Firmware · 292H500s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211Solidfire · 192