CVE-2024-8373
Netapp Active Iq Unified Manager
Raw vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:LSummary
CVE-2024-8373 is a medium-severity Incomplete Filtering of Special Elements (CWE-791) vulnerability in Netapp Active Iq Unified Manager. Its CVSS base score is 4.8 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 46th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-2837
Vulnerability Data
Improper sanitization of the value of the [srcset] attribute in <source> HTML elements in AngularJS allows attackers to bypass common image source restrictions, which can also lead to a form of Content Spoofing https://owasp.org/www-community/attacks/Content_Spoofing . This issue affects all versions…
more
of AngularJS. Note: The AngularJS project is End-of-Life and will not receive any updates to address this issue. For more information see here https://docs.angularjs.org/misc/version-support-status .
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Input validation directly requires complete filtering of special elements on received data before further processing or forwarding.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly require complete input filtering and sanitization to prevent this weakness.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Security testing in development and acceptance can detect incomplete filtering but does not itself implement the filtering.
Secure development life cycle processes include validation activities that reduce the likelihood of CWE-791 but do not specify the control itself.
Application security requirements explicitly call for input validation and sanitization that directly mitigates incomplete special-element filtering.
Secure system architecture and engineering principles require defensive design patterns that prevent unfiltered data from reaching downstream components.
Secure coding standards mandate complete filtering and escaping of special elements, directly eliminating CWE-791.