CVE-2025-24970: Netapp Active Iq Unified Manager
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final and prior to version 4.1.118.Final. When a special crafted packet is received via SslHandler it doesn't correctly handle validation of such a packet in all cases which can lead to a native crash. Version 4.1.118.Final contains a patch. As workaround its possible to either disable the usage of the native SSLEngine or change the code manually.
Affected products
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Oncommand Insight: affected versions not specified
- Netty Netty: from 4.1.91, before 4.1.118 (fixed in 4.1.118)
Published 2025-02-10. Last modified 2026-06-17.