« Back to list

Netapp

Netapp H410s Firmware: vulnerabilities and CVEs

Netapp H410s Firmware has 292 published vulnerabilities, 0 of them in the last 12 months. 16 are rated critical and 12 are listed by CISA as actively exploited.

CVEs292
Last 12 months0
Critical16
Actively exploited12

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-0995High (7.8)8.8%⚠ Active exploitationMar 25, 2022
An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged…
CVE-2022-0492High (7.8)5.5%⚠ Active exploitationMar 3, 2022
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to…
CVE-2021-22555High (7.8)79%⚠ Active exploitationJul 7, 2021
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
CVE-2024-54085Critical (10)61%⚠ Active exploitationMar 11, 2025
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of…
CVE-2023-0386High (7.8)7.9%⚠ Active exploitationMar 22, 2023
A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid…
CVE-2020-11023Medium (6.1)85%⚠ Active exploitationApr 29, 2020
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.…
CVE-2022-0185High (8.4)25%⚠ Active exploitationFeb 11, 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of…
CVE-2024-1086High (7.8)28%⚠ Active exploitationJan 31, 2024
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the…
CVE-2023-4911High (7.8)81%⚠ Active exploitationOct 3, 2023
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES…
CVE-2022-0847High (7.8)93%⚠ Active exploitationMar 10, 2022
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale…
CVE-2021-22600High (7)6.6%⚠ Active exploitationJan 26, 2022
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions…
CVE-2019-2215High (7.8)72%⚠ Active exploitationOct 11, 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-54085Critical (10)61%⚠ Active exploitationMar 11, 2025
AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of…
CVE-2025-24928High (7.7)0.39%—Feb 18, 2025
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a stack-based buffer overflow in xmlSnprintfElements in valid.c. To exploit this, DTD validation must occur for an untrusted document or untrusted DTD. NOTE: this is…
CVE-2024-56171Critical (9.8)1.2%—Feb 18, 2025
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an…
CVE-2025-0665High (7)1.3%—Feb 5, 2025
libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resolve.
CVE-2025-0167Low (3.4)0.69%—Feb 5, 2025
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests…
CVE-2024-40896Critical (9.1)1.2%—Dec 23, 2024
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This…
CVE-2024-11053Low (3.4)1.3%—Dec 11, 2024
When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests…
CVE-2024-50602Medium (5.9)1.0%—Oct 27, 2024
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
CVE-2024-8096Medium (6.5)0.73%—Sep 11, 2024
When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly…
CVE-2024-6119High (7.5)67%—Sep 3, 2024
Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process.…
CVE-2024-36958Medium (5.5)0.50%—May 30, 2024
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of…
CVE-2024-33602High (7.4)0.40%—May 6, 2024
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw…
CVE-2024-33601High (7.3)1.1%—May 6, 2024
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory…
CVE-2024-33600Medium (5.9)1.2%—May 6, 2024
nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache fails to add a not-found netgroup response to the cache, the client request can result in a null pointer dereference.…
CVE-2024-33599High (8.1)1.3%—May 6, 2024
nscd: Stack-based buffer overflow in netgroup cache If the Name Service Cache Daemon's (nscd) fixed size cache is exhausted by client requests then a subsequent client request for netgroup data may result in a…
CVE-2024-2466Medium (6.5)1.3%—Mar 27, 2024
libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified…
CVE-2024-2398High (8.6)36%—Mar 27, 2024
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl…
CVE-2024-2379Medium (6.3)1.7%—Mar 27, 2024
libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and…
CVE-2024-2004Low (3.5)1.7%—Mar 27, 2024
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below…
CVE-2024-28757High (7.5)2.0%—Mar 10, 2024
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
CVE-2024-1086High (7.8)28%⚠ Active exploitationJan 31, 2024
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the…
CVE-2023-5363High (7.5)3.3%—Oct 25, 2023
Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact…
CVE-2023-40791Medium (6.3)0.45%—Oct 16, 2023
extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page.
CVE-2023-4911High (7.8)81%⚠ Active exploitationOct 3, 2023
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES…
CVE-2023-4236High (7.5)2.2%—Sep 20, 2023
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant…
CVE-2023-4527Medium (6.5)1.7%—Sep 18, 2023
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can…
CVE-2023-4813Medium (5.9)1.9%—Sep 12, 2023
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function…
CVE-2023-4273Medium (6.7)0.65%—Aug 9, 2023
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory…
CVE-2023-32252High (7.5)4.1%—Jul 24, 2023
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_LOGOFF commands. The issue results from the lack of proper validation of a…
CVE-2023-3212Medium (4.4)0.26%—Jun 23, 2023
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1204.001 Malicious Link1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Netapp