Netapp
Netapp H700e Firmware: vulnerabilidades y CVE
Netapp H700e Firmware tiene 149 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 6 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE149
Últimos 12 meses0
Críticas6
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0995 | Alta (7.8) | 8.8% | ⚠ Explotación activa | 25 mar 2022 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged… |
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2022-0185 | Alta (8.4) | 25% | ⚠ Explotación activa | 11 feb 2022 | A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of… |
| CVE-2022-0847 | Alta (7.8) | 93% | ⚠ Explotación activa | 10 mar 2022 | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1882 | Alta (7.8) | 0.36% | — | 26 may 2022 | A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a… |
| CVE-2022-1678 | Alta (7.5) | 2.9% | — | 25 may 2022 | An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. |
| CVE-2022-1734 | Alta (7) | 0.53% | — | 18 may 2022 | A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. |
| CVE-2022-29581 | Alta (7.8) | 0.93% | — | 17 may 2022 | Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later… |
| CVE-2022-1679 | Alta (7.8) | 0.81% | — | 16 may 2022 | A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to… |
| CVE-2022-29155 | Crítica (9.8) | 64% | — | 4 may 2022 | In OpenLDAP 2.x before 2.5.12 and 2.6.x before 2.6.2, a SQL injection vulnerability exists in the experimental back-sql backend to slapd, via a SQL statement within an LDAP query. This can occur during an LDAP search… |
| CVE-2022-1473 | Alta (7.5) | 2.5% | — | 3 may 2022 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a… |
| CVE-2022-1434 | Media (5.9) | 1.1% | — | 3 may 2022 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a… |
| CVE-2022-1343 | Media (5.3) | 1.2% | — | 3 may 2022 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)… |
| CVE-2022-1292 | Alta (7.3) | 83% | — | 3 may 2022 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating… |
| CVE-2022-1353 | Alta (7.1) | 0.40% | — | 29 abr 2022 | A vulnerability was found in the pfkey_register function in net/key/af_key.c in the Linux kernel. This flaw allows a local, unprivileged user to gain access to kernel memory, leading to a system crash or a leak of… |
| CVE-2022-1048 | Alta (7) | 0.24% | — | 29 abr 2022 | A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls.… |
| CVE-2022-29156 | Alta (7.8) | 0.38% | — | 13 abr 2022 | drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. |
| CVE-2022-28893 | Alta (7.8) | 0.41% | — | 11 abr 2022 | The SUNRPC subsystem in the Linux kernel through 5.17.2 can call xs_xprt_free before ensuring that sockets are in the intended state. |
| CVE-2022-28796 | Alta (7) | 0.33% | — | 8 abr 2022 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. |
| CVE-2022-28389 | Media (5.5) | 0.32% | — | 3 abr 2022 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-28388 | Media (5.5) | 0.40% | — | 3 abr 2022 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. |
| CVE-2022-0998 | Alta (7.8) | 0.37% | — | 30 mar 2022 | An integer overflow flaw was found in the Linux kernel’s virtio device driver code in the way a user triggers the vhost_vdpa_config_validate function. This flaw allows a local user to crash or potentially escalate their… |
| CVE-2022-1055 | Alta (8.6) | 0.50% | — | 29 mar 2022 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit… |
| CVE-2022-0995 | Alta (7.8) | 8.8% | ⚠ Explotación activa | 25 mar 2022 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged… |
| CVE-2022-0500 | Alta (7.8) | 0.36% | — | 25 mar 2022 | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to… |
| CVE-2022-0435 | Alta (8.8) | 68% | — | 25 mar 2022 | A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw… |
| CVE-2022-0330 | Alta (7.8) | 0.38% | — | 25 mar 2022 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their… |
| CVE-2021-4157 | Alta (8) | 1.6% | — | 25 mar 2022 | An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could… |
| CVE-2021-25220 | Media (6.8) | 3.4% | — | 23 mar 2022 | BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported… |
| CVE-2022-0635 | Alta (7.5) | 1.3% | — | 23 mar 2022 | Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check. |
| CVE-2022-0396 | Media (5.3) | 2.7% | — | 23 mar 2022 | BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an… |
| CVE-2022-27666 | Alta (7.8) | 5.5% | — | 23 mar 2022 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may… |
| CVE-2022-0667 | Alta (7.5) | 1.3% | — | 22 mar 2022 | When the vulnerability is triggered the BIND process will exit. BIND 9.18.0 |
| CVE-2022-1011 | Alta (7.8) | 1.2% | — | 18 mar 2022 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H410s Firmware · 292H500s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211