This is a real Visual One Intelligence security assessment with the client’s name removed. Findings 1 to 3 are open below. Findings 4 to 26, the remediation plan, and the methodology take one form.
Skip to the complete reportTwenty-five CVEs with confirmed NVD or CVE.org records apply to firmware and software actively running across the ACME Widget estate as of the July 14, 2026 collection — 11 Critical, 11 High, 3 Medium — including 3 CVEs on the CISA Known Exploited Vulnerabilities (KEV) catalog.
| Resource Group | Assets in Scope | KEV | Critical | High | Medium |
|---|---|---|---|---|---|
| Storage Arrays | 33 | 0 | 6 | 4 | 3 |
| Virtual Compute Servers | 556 hosts / 6 vCenters + 9 HMC | 3 | 5 | 2 | 0 |
| SAN Switches | 16 | 0 | 0 | 5 | 0 |
| Fleet Total | 33 + 556 hosts + 16 | 3 | 11 | 11 | 3 |
Confirm the exact ESXi/vCenter build string (not the “8.0.3” branch label) on all 556 hosts and 6 vCenter instances. If any host predates ESXi80U3d (build 24585383) or any vCenter predates 8.0U2d, it is exposed to actively-exploited, KEV-listed ransomware vulnerabilities today. See Section 03.
Six devices — two IBM Storwize V7000 pairs and one IBM SAN Volume Controller — carry CVE-2022-0778 (CVSS 7.5, public proof-of-concept exists). Correction from an earlier draft of this report: CVE-2022-0778 is not on the CISA KEV catalog — the March 2022 date associated with it is OpenSSL’s patch-release date, not a KEV addition date; it has been removed from the KEV count below. The three genuinely KEV-listed CVEs in this estate are all VMware/Broadcom vCenter and ESXi vulnerabilities (Section 03). Two Dell EMC Data Domain backup targets run a DD OS branch (7.1.0.x) Dell no longer issues point-fixes for, so two Critical CVEs cannot be remediated without a major-version upgrade. Six Brocade switches sit on the fabric’s oldest firmware train (v8.2.2d) and carry two High-severity CVEs already closed on sibling switches in the same fabric.
Beyond CVE exposure, direct cross-reference of 4,914 VM records (Section 04) and 6 IBM Spectrum Protect backup servers (Section 05) against raw VisualOne export data surfaced 10 additional hidden security gems (Section 06) — most notably a backup server running a 2017-era, unsupported software release with authentication controls effectively disabled, and 981 of 988 backup-client node credentials fleet-wide left unlocked, some dormant for nearly 7 years.
Thirty-three storage devices across 8 platforms reported a firmware or OS version in the July 14, 2026 collection; 13 confirmed CVEs apply across 6 of those platforms.
| Vendor | Product | Observed Firmware | Devices | Role |
|---|---|---|---|---|
| Dell EMC Data Domain | DD OS | 7.1.0.40-663551 | 2 | Backup target |
| Dell EMC XtremIO | XIOS | 4.0.27 | 1 | All-flash array (Gen-1) |
| HPE Nimble / Nimble Alletra | NimbleOS | 6.1.3.300-1084694-opt | 7 | Hybrid/all-flash array |
| HPE Primera | Primera OS | 4.6.5.19 | 1 | Tier-1 array |
| HPE Primera | Primera OS | 4.6.20.6 | 5 | Tier-1 array |
| HPE 3PAR StoreServ | 3PAR OS | 3.2.2.709 | 1 | Tier-1/2 array — EOL, unresearched |
| HPE 3PAR StoreServ | 3PAR OS | 3.3.2.159 | 4 | Tier-1/2 array |
| NetApp FAS (cluster pair) | ONTAP | 9.18.1P1 | 1 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.16.1P6 | 2 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.11.1P20 | 2 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.8P21 | 1 | NAS/unified — past Limited Support |
| IBM Storwize V7000 | Spectrum Virtualize | 7.8.1.11 | 2 | Block storage |
| IBM Storwize V7000 | Spectrum Virtualize | 7.8.1.14 | 3 | Block storage |
| IBM SAN Volume Controller | Spectrum Virtualize | 8.2.1.11 | 1 | Storage virtualization |
| Fleet Total (firmware-confirmed) | 33 | 8 platforms | ||
Observed: Storwize 7.8.1.11 (2) + 7.8.1.14 (3) + SVC 8.2.1.11 (1) • 6 devices — all below fix • Affected range: 7.8 / 8.2 / 8.3 / 8.4 / 8.5 branches
Observed: DD OS 7.1.0.40-663551 • 2 devices • Affected range: 7.0 – 7.10 (includes 7.1.0.x)
Observed: XIOS 4.0.27 • 1 device (Gen-1 hardware — presumed never migrated past XMS 6.x; XMS build not independently confirmed) • Affected range: XMS prior to 6.4.0-22
This is a sanitized sample of a real Visual One Intelligence security assessment. Client identifiers have been anonymized. Your copy of the full report opens immediately after submission.
Work email gets you straight in. No PDF download, no wait.