NetApp Active IQ Unified Manager and OnCommand Insight contain a remote code execution…
NetApp Active IQ Unified Manager and OnCommand Insight contain a remote code execution vulnerability (CVE-2023-22102) affecting Windows and VMware deployments.
NetApp has disclosed a vulnerability in multiple product lines that enables remote code execution. The flaw affects Active IQ Unified Manager for both Microsoft Windows and VMware vSphere platforms, as well as OnCommand Insight. Vulnerable versions include Active IQ Unified Manager for Windows prior to 9.16P2D23 and prior to 9.18D11/9.18P1, Active IQ Unified Manager for VMware vSphere prior to 9.16P2D23 and prior to 9.18D11/9.18P1, and OnCommand Insight prior to 7.3.15.
The vulnerability is tracked as CVE-2023-22102 and allows an attacker to achieve arbitrary remote code execution. NetApp has released patches to address the vulnerability across affected product versions. Organizations running these NetApp management platforms should prioritize applying the vendor-provided updates to mitigate the remote code execution risk.
Given the remote code execution impact and the widespread deployment of NetApp management tools in enterprise environments, particularly in infrastructure and storage management contexts, this vulnerability poses a significant risk to affected organizations.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0656
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free