CVE-2022-23240: Medium severity netapp active iq unified manager vulnerability
Published Feb 28, 2023
·Updated
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
Affected Software
3 affected components
NetApp Active Iq Unified Manager Linux<9.11p1
NetApp Active Iq Unified Manager Vmware Vsphere<9.11p1
NetApp Active Iq Unified Manager Windows<9.11p1
Remediation
Patch Available
Event History
Feb 28, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-23240.
2
Which software versions are affected by the vulnerability?
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are affected.
3
What is the severity of the vulnerability?
The severity of CVE-2022-23240 is medium with a severity value of 6.5.
4
How can unauthorized users exploit this vulnerability?
Unauthorized users can exploit this vulnerability to update EMS Subscriptions via unspecified vectors.
5
Is there a fix available for this vulnerability?
Yes, the fix for CVE-2022-23240 is available. Please refer to the vendor's advisory for more information.