Sample Report • Real Findings • Anonymized Client

25 confirmed CVEs. 3 already being exploited in the wild. One infrastructure estate.

This is a real Visual One Intelligence security assessment with the client’s name removed. Findings 1 to 3 are open below. Findings 4 to 26, the remediation plan, and the methodology take one form.

Skip to the complete report
Visual One Intelligence Platform
ACME Widget Security Analysis
CVE exposure, VM-level security posture, and raw-data hidden-gem findings across storage arrays, virtual compute servers, backup infrastructure, and SAN switches.
July 14, 2026
Visual One Intelligence
33 Arrays 4,914 VMs 6 Backup Servers 16 Switches
ACME Widget
3
1

Executive Summary

Twenty-five CVEs with confirmed NVD or CVE.org records apply to firmware and software actively running across the ACME Widget estate as of the July 14, 2026 collection — 11 Critical, 11 High, 3 Medium — including 3 CVEs on the CISA Known Exploited Vulnerabilities (KEV) catalog.

11
Critical CVEs
CVSS ≥ 9.0, confirmed applicable
3
KEV-Listed CVEs
Confirmed active exploitation per CISA
11
High CVEs
CVSS 7.0–8.9
26
Total Findings
25 CVEs + 1 end-of-support finding
25
Assets w/ Confirmed Exposure
Across storage, virtual, and fabric
556
Hosts Pending Build Verification
Fleet-wide KEV exposure window (Section 03)

Exposure by Resource Group

Resource GroupAssets in ScopeKEVCriticalHighMedium
Storage Arrays330643
Virtual Compute Servers556 hosts / 6 vCenters + 9 HMC3520
SAN Switches160050
Fleet Total33 + 556 hosts + 16311113
Immediate Action

Confirm the exact ESXi/vCenter build string (not the “8.0.3” branch label) on all 556 hosts and 6 vCenter instances. If any host predates ESXi80U3d (build 24585383) or any vCenter predates 8.0U2d, it is exposed to actively-exploited, KEV-listed ransomware vulnerabilities today. See Section 03.

Six devices — two IBM Storwize V7000 pairs and one IBM SAN Volume Controller — carry CVE-2022-0778 (CVSS 7.5, public proof-of-concept exists). Correction from an earlier draft of this report: CVE-2022-0778 is not on the CISA KEV catalog — the March 2022 date associated with it is OpenSSL’s patch-release date, not a KEV addition date; it has been removed from the KEV count below. The three genuinely KEV-listed CVEs in this estate are all VMware/Broadcom vCenter and ESXi vulnerabilities (Section 03). Two Dell EMC Data Domain backup targets run a DD OS branch (7.1.0.x) Dell no longer issues point-fixes for, so two Critical CVEs cannot be remediated without a major-version upgrade. Six Brocade switches sit on the fabric’s oldest firmware train (v8.2.2d) and carry two High-severity CVEs already closed on sibling switches in the same fabric.

Beyond CVE exposure, direct cross-reference of 4,914 VM records (Section 04) and 6 IBM Spectrum Protect backup servers (Section 05) against raw VisualOne export data surfaced 10 additional hidden security gems (Section 06) — most notably a backup server running a 2017-era, unsupported software release with authentication controls effectively disabled, and 981 of 988 backup-client node credentials fleet-wide left unlocked, some dormant for nearly 7 years.

2

Storage Arrays

Thirty-three storage devices across 8 platforms reported a firmware or OS version in the July 14, 2026 collection; 13 confirmed CVEs apply across 6 of those platforms.

Estate Inventory — Firmware Confirmed

VendorProductObserved FirmwareDevicesRole
Dell EMC Data DomainDD OS7.1.0.40-6635512Backup target
Dell EMC XtremIOXIOS4.0.271All-flash array (Gen-1)
HPE Nimble / Nimble AlletraNimbleOS6.1.3.300-1084694-opt7Hybrid/all-flash array
HPE PrimeraPrimera OS4.6.5.191Tier-1 array
HPE PrimeraPrimera OS4.6.20.65Tier-1 array
HPE 3PAR StoreServ3PAR OS3.2.2.7091Tier-1/2 array — EOL, unresearched
HPE 3PAR StoreServ3PAR OS3.3.2.1594Tier-1/2 array
NetApp FAS (cluster pair)ONTAP9.18.1P11NAS/unified
NetApp FAS (cluster pair)ONTAP9.16.1P62NAS/unified
NetApp FAS (cluster pair)ONTAP9.11.1P202NAS/unified
NetApp FAS (cluster pair)ONTAP9.8P211NAS/unified — past Limited Support
IBM Storwize V7000Spectrum Virtualize7.8.1.112Block storage
IBM Storwize V7000Spectrum Virtualize7.8.1.143Block storage
IBM SAN Volume ControllerSpectrum Virtualize8.2.1.111Storage virtualization
Fleet Total (firmware-confirmed)338 platforms
Coverage gap: Pure FlashArray/FlashBlade (3), Dell PowerMax, PowerStore, Unity, HPE Alletra 9080 (2), Cohesity (5 clusters), Nutanix, VAST (2), Qumulo, Hitachi VSP, IBM FS9500 (2), IBM DS8000 (2, unmanaged), Scality (2) — confirmed present in the estate via device inventory but firmware/microcode was not captured by VisualOne telemetry for the July 14, 2026 collection; no CVE analysis possible without a version string.

Findings, Ranked

1
CVE-2022-0778 — IBM Spectrum Virtualize (Storwize V7000 + SVC)
7.5 HIGH (NVD) Risk: HIGH Not KEV-listed

Observed: Storwize 7.8.1.11 (2) + 7.8.1.14 (3) + SVC 8.2.1.11 (1) 6 devices — all below fix    Affected range: 7.8 / 8.2 / 8.3 / 8.4 / 8.5 branches

Vulnerability Evidence: Public PoC exists (GitHub) and this OpenSSL flaw was broadly exploited across other vendors’ products; not itself on the CISA KEV catalog for this CVE ID NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-0778
Remediation: Update to 7.8.1.15 (Storwize) / 8.2.1.16 (SVC). Vendor advisory: IBM ibm6622017 — https://www.ibm.com/support/pages/ibm-security-advisory
Risk if Unresolved: OpenSSL BN_mod_sqrt() infinite loop (DoS). A public PoC exists — treat as HIGH priority despite the absence of a KEV listing.
2
CVE-2022-31813 — Dell EMC Data Domain (DD OS)
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: DD OS 7.1.0.40-663551 2 devices    Affected range: 7.0 – 7.10 (includes 7.1.0.x)

Vulnerability Evidence: Apache mod_proxy X-Forwarded-* auth-bypass technique is publicly documented (upstream Apache advisory); no DD-specific PoC confirmed NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-31813
Remediation: Correction from an earlier draft: this CVE is addressed under Dell advisory DSA-2023-389 (not DSA-2022-302, which does not reference this CVE) — the same advisory covering CVE-2022-36760 below. Update to 7.12.0.0+ / 7.7.5.20+ (LTS2022) / 7.10.1.10+ (LTS2023) — no 7.1.x point-fix exists. Vendor advisory: Dell DSA-2023-389 — https://www.dell.com/support/kbdoc/en-us/000218619
Risk if Unresolved: DD OS 7.1.0.x is a superseded branch — Dell’s fix requires a full upgrade to a current LTS/GA branch, not an in-branch patch.
3
CVE-2022-31228 — Dell EMC XtremIO (XMS)
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: XIOS 4.0.27 1 device (Gen-1 hardware — presumed never migrated past XMS 6.x; XMS build not independently confirmed)    Affected range: XMS prior to 6.4.0-22

Vulnerability Evidence: Unauthenticated brute-force admin-account takeover; no confirmed public PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-31228
Remediation: Update to XMS 6.4.0-22. Vendor advisory: Dell DSA-2022-145 — https://www.dell.com/support/kbdoc/en-us/000204112
Risk if Unresolved: Dell tracks the fix against XMS version, not XIOS. A device still on XIOS 4.0.27 almost certainly predates the 6.x XMS line — treated as presumed-affected pending direct XMS build confirmation.
Complete Report

You’ve seen 3 of 26 findings.

  • Findings 4 through 26, ranked, across virtual compute, VM security, backup infrastructure, and SAN switches
  • 3 KEV-listed VMware CVEs with exact build-string remediation targets for 556 hosts
  • 981 of 988 backup node credentials left unlocked, plus 9 more hidden security gems pulled from raw export data
  • The full remediation plan, sequenced by risk and effort
  • Methodology, data sources, vulnerability feeds queried, and known coverage gaps

This is a sanitized sample of a real Visual One Intelligence security assessment. Client identifiers have been anonymized. Your copy of the full report opens immediately after submission.

Read the complete report

Work email gets you straight in. No PDF download, no wait.

3 of 26 findings open. The rest take one form.
Get the full report