CVE-2022-23237: Medium severity netapp e-series santricity os controller vulnerability
Published Jun 1, 2022
·Updated
E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.
Affected Software
1 affected component
NetApp E-Series SANtricity OS Controller>=11.0.0<=11.70.2
Event History
Jun 1, 2022
CVE Published
via MITRE·01:54 PM
Data Sourced
via MITRE·01:54 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2022-23237?
CVE-2022-23237 is a vulnerability that affects E-Series SANtricity OS Controller Software 11.x versions through 11.70.2.
2
What is the severity of CVE-2022-23237?
The severity of CVE-2022-23237 is medium with a CVSS score of 6.1.
3
How does CVE-2022-23237 impact the affected software?
CVE-2022-23237 allows for host header injection attacks, which can redirect users to malicious websites.
4
Which version of E-Series SANtricity OS Controller Software is affected by CVE-2022-23237?
E-Series SANtricity OS Controller Software versions 11.x through 11.70.2 are vulnerable.
5
How can the CVE-2022-23237 vulnerability be fixed?
To fix CVE-2022-23237, it is recommended to update E-Series SANtricity OS Controller Software to a version higher than 11.70.2.