CVE-2022-23240
published 2023-02-28CVE-2022-23240: Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.41%
33.5th percentile
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| netapp | active_iq_unified_manager | < 9.11p1 | 9.11p1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NetApp Active IQ Unified Manager for VMware up to 9.11 EMS Subscription access control (ntap-20220901-0002 / EUVD-2022-28327)
vuldb·2026-04-30·CVSS 6.5
CVE-2022-23240 [MEDIUM] NetApp Active IQ Unified Manager for VMware up to 9.11 EMS Subscription access control (ntap-20220901-0002 / EUVD-2022-28327)
A vulnerability described as critical has been identified in NetApp Active IQ Unified Manager for VMware up to 9.11. This affects an unknown function of the component EMS Subscription Handler. Executing a manipulation can lead to improper access controls.
This vulnerability is registered as CVE-2022-23240. The attack requires access to the local network. No exploit is available.
A patch should be applied to remediate this issue.
GHSA
GHSA-2j4p-2hc9-62f4: Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9
ghsa_unreviewed·2023-03-01
CVE-2022-23240 [MEDIUM] CWE-284 GHSA-2j4p-2hc9-62f4: Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9
Active IQ Unified Manager for VMware vSphere, Linux, and Microsoft Windows versions prior to 9.11P1 are susceptible to a vulnerability which allows unauthorized users to update EMS Subscriptions via unspecified vectors.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-02-28
Published