SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-23237

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

MEDIUM 6.1EPSS 0.60%

Does this matter?

Lower severity and a low EPSS score (0.60%). Track it; it rarely justifies an emergency change on its own.

Description

E-Series SANtricity OS Controller Software 11.x versions through 11.70.2 are vulnerable to host header injection attacks that could allow an attacker to redirect users to malicious websites.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
0.60% probability · 47th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
netapp/e-series santricity os controller
Source
security-alert@netapp.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.