CVE-2022-23235: Medium severity netapp active iq unified manager vulnerability
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 are susceptible to a vulnerability which could allow an attacker to discover cluster, node and Active IQ Unified Manager specific information via AutoSupport telemetry data that is sent even when AutoSupport has been disabled.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-23235?
CVE-2022-23235 is a vulnerability in Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.10P1 that allows an attacker to discover cluster, node, and Active IQ Unified Manager specific information via AutoSupport telemetry data.
Which software versions are affected by CVE-2022-23235?
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions up to exclusive 9.10 are affected by CVE-2022-23235.
What is the severity of CVE-2022-23235?
CVE-2022-23235 has a severity rating of 5.3 (Medium).
How can an attacker exploit CVE-2022-23235?
An attacker can exploit CVE-2022-23235 by intercepting the AutoSupport telemetry data sent by Active IQ Unified Manager and extracting cluster, node, and Active IQ Unified Manager specific information.
Is there a patch or update available for CVE-2022-23235?
Yes, the vulnerability can be fixed by upgrading Active IQ Unified Manager to version 9.10P1 or later.