<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Active IQ Unified Manager — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/active-iq-unified-manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 28 May 2026 11:34:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/active-iq-unified-manager/feed.xml" rel="self" type="application/rss+xml"/><item><title>NetApp Active IQ Unified Manager and OnCommand Insight Remote Code Execution Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-05-netapp-rce/</link><pubDate>Thu, 28 May 2026 11:34:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-netapp-rce/</guid><description>CVE-2023-22102 describes a vulnerability in NetApp Active IQ Unified Manager and OnCommand Insight that allows a remote attacker to execute arbitrary code.</description><content:encoded><![CDATA[<p>A remote code execution vulnerability, tracked as CVE-2023-22102, has been discovered in NetApp Active IQ Unified Manager and OnCommand Insight. This vulnerability impacts Active IQ Unified Manager for Microsoft Windows versions prior to 9.16P2D23, versions prior to 9.18D11 or 9.18P1, Active IQ Unified Manager for VMware vSphere versions prior to 9.16P2D23, versions prior to 9.18D11 or 9.18P1, and OnCommand Insight versions prior to 7.3.15. Successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the affected system. NetApp has released security bulletin NTAP-20231027-0007 on May 27, 2026, to address this vulnerability.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An unauthenticated attacker identifies a vulnerable NetApp Active IQ Unified Manager or OnCommand Insight instance exposed to the network.</li>
<li>The attacker crafts a malicious request, exploiting the CVE-2023-22102 vulnerability.</li>
<li>The request is sent to the targeted NetApp server via the network (likely over HTTP/HTTPS).</li>
<li>The vulnerable component processes the malicious request, failing to properly sanitize or validate the input.</li>
<li>This leads to arbitrary code execution within the context of the application.</li>
<li>The attacker gains control over the compromised system.</li>
<li>The attacker can then perform further actions such as installing malware, accessing sensitive data, or pivoting to other systems within the network.</li>
<li>The final objective is likely data exfiltration, disruption of services, or further lateral movement.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2023-22102 can lead to complete compromise of the affected NetApp Active IQ Unified Manager or OnCommand Insight server. This can result in data loss, disruption of management operations, and potential lateral movement to other systems within the network, depending on the permissions and network access of the compromised server. The potential impact ranges from loss of confidentiality and integrity to a complete shutdown of critical services managed by the compromised NetApp product.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately patch all affected NetApp Active IQ Unified Manager and OnCommand Insight instances to the latest versions specified in the NetApp security bulletin NTAP-20231027-0007.</li>
<li>Monitor network traffic for suspicious activity targeting NetApp Active IQ Unified Manager and OnCommand Insight servers using the provided Sigma rules.</li>
<li>Review and harden network segmentation to limit the blast radius of a potential compromise.</li>
<li>Apply the principle of least privilege to the NetApp Active IQ Unified Manager and OnCommand Insight server accounts to restrict the impact of potential code execution.</li>
<li>Regularly audit and review the security configuration of NetApp Active IQ Unified Manager and OnCommand Insight instances.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>rce</category><category>netapp</category><category>cve-2023-22102</category></item></channel></rss>