Netapp
Netapp Smi-s Provider: vulnerabilidades y CVE
Netapp Smi-s Provider tiene 19 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses0
Críticas0
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-29552 | Alta (7.5) | 64% | ⚠ Explotación activa | 25 abr 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-29552 | Alta (7.5) | 64% | ⚠ Explotación activa | 25 abr 2023 | The Service Location Protocol (SLP, RFC 2608) allows an unauthenticated, remote attacker to register arbitrary services. This could allow the attacker to use spoofed UDP traffic to conduct a denial-of-service attack… |
| CVE-2022-40304 | Alta (7.8) | 5.8% | — | 23 nov 2022 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked. |
| CVE-2022-2068 | Alta (7.3) | 95% | — | 21 jun 2022 | In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by… |
| CVE-2022-1473 | Alta (7.5) | 2.5% | — | 3 may 2022 | The OPENSSL_LH_flush() function, which empties a hash table, contains a bug that breaks reuse of the memory occuppied by the removed hash table entries. This function is used when decoding certificates or keys. If a… |
| CVE-2022-1434 | Media (5.9) | 1.1% | — | 3 may 2022 | The OpenSSL 3.0 implementation of the RC4-MD5 ciphersuite incorrectly uses the AAD data as the MAC key. This makes the MAC key trivially predictable. An attacker could exploit this issue by performing a… |
| CVE-2022-1343 | Media (5.3) | 1.2% | — | 3 may 2022 | The function `OCSP_basic_verify` verifies the signer certificate on an OCSP response. In the case where the (non-default) flag OCSP_NOCHECKS is used then the response will be positive (meaning a successful verification)… |
| CVE-2022-1292 | Alta (7.3) | 83% | — | 3 may 2022 | The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating… |
| CVE-2022-29824 | Media (6.5) | 3.8% | — | 3 may 2022 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to… |
| CVE-2022-23308 | Alta (7.5) | 5.1% | — | 26 feb 2022 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
| CVE-2021-3541 | Media (6.5) | 2.0% | — | 9 jul 2021 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms and leading to denial of service. |
| CVE-2020-15862 | Alta (7.8) | 0.38% | — | 20 ago 2020 | Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. |
| CVE-2020-15861 | Alta (7.8) | 0.46% | — | 20 ago 2020 | Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |
| CVE-2020-1967 | Alta (7.5) | 53% | — | 21 abr 2020 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"… |
| CVE-2020-7595 | Alta (7.5) | 7.8% | — | 21 ene 2020 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
| CVE-2019-20388 | Alta (7.5) | 3.1% | — | 21 ene 2020 | xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
| CVE-2019-1559 | Media (5.9) | 17% | — | 27 feb 2019 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte… |
| CVE-2018-0735 | Media (5.9) | 4.7% | — | 29 oct 2018 | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j… |
| CVE-2016-8610 | Alta (7.5) | 40% | — | 13 nov 2017 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use… |
| CVE-2015-8960 | Alta (8.1) | 1.9% | — | 21 sept 2016 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in… |
Otros productos de Netapp
Oncommand Insight · 971Active IQ Unified Manager · 848Oncommand Workflow Automation · 743Snapcenter · 575Cloud Backup · 349H700s Firmware · 293H300s Firmware · 292H500s Firmware · 292H410s Firmware · 292E-series Santricity OS Controller · 242H410c Firmware · 240Steelstore Cloud Integrated Storage · 211