Visual One Intelligence Platform
ACME Widget Security Analysis
CVE exposure, VM-level security posture, and raw-data hidden-gem findings across storage arrays, virtual compute servers, backup infrastructure, and SAN switches.
July 14, 2026
Visual One Intelligence
33 Arrays 4,914 VMs 6 Backup Servers 16 Switches
ACME Widget
3
1

Executive Summary

Twenty-five CVEs with confirmed NVD or CVE.org records apply to firmware and software actively running across the ACME Widget estate as of the July 14, 2026 collection — 11 Critical, 11 High, 3 Medium — including 3 CVEs on the CISA Known Exploited Vulnerabilities (KEV) catalog.

11
Critical CVEs
CVSS ≥ 9.0, confirmed applicable
3
KEV-Listed CVEs
Confirmed active exploitation per CISA
11
High CVEs
CVSS 7.0–8.9
26
Total Findings
25 CVEs + 1 end-of-support finding
25
Assets w/ Confirmed Exposure
Across storage, virtual, and fabric
556
Hosts Pending Build Verification
Fleet-wide KEV exposure window (Section 03)

Exposure by Resource Group

Resource GroupAssets in ScopeKEVCriticalHighMedium
Storage Arrays330643
Virtual Compute Servers556 hosts / 6 vCenters + 9 HMC3520
SAN Switches160050
Fleet Total33 + 556 hosts + 16311113
Immediate Action

Confirm the exact ESXi/vCenter build string (not the “8.0.3” branch label) on all 556 hosts and 6 vCenter instances. If any host predates ESXi80U3d (build 24585383) or any vCenter predates 8.0U2d, it is exposed to actively-exploited, KEV-listed ransomware vulnerabilities today. See Section 03.

Six devices — two IBM Storwize V7000 pairs and one IBM SAN Volume Controller — carry CVE-2022-0778 (CVSS 7.5, public proof-of-concept exists). Correction from an earlier draft of this report: CVE-2022-0778 is not on the CISA KEV catalog — the March 2022 date associated with it is OpenSSL’s patch-release date, not a KEV addition date; it has been removed from the KEV count below. The three genuinely KEV-listed CVEs in this estate are all VMware/Broadcom vCenter and ESXi vulnerabilities (Section 03). Two Dell EMC Data Domain backup targets run a DD OS branch (7.1.0.x) Dell no longer issues point-fixes for, so two Critical CVEs cannot be remediated without a major-version upgrade. Six Brocade switches sit on the fabric’s oldest firmware train (v8.2.2d) and carry two High-severity CVEs already closed on sibling switches in the same fabric.

Beyond CVE exposure, direct cross-reference of 4,914 VM records (Section 04) and 6 IBM Spectrum Protect backup servers (Section 05) against raw VisualOne export data surfaced 10 additional hidden security gems (Section 06) — most notably a backup server running a 2017-era, unsupported software release with authentication controls effectively disabled, and 981 of 988 backup-client node credentials fleet-wide left unlocked, some dormant for nearly 7 years.

2

Storage Arrays

Thirty-three storage devices across 8 platforms reported a firmware or OS version in the July 14, 2026 collection; 13 confirmed CVEs apply across 6 of those platforms.

Estate Inventory — Firmware Confirmed

VendorProductObserved FirmwareDevicesRole
Dell EMC Data DomainDD OS7.1.0.40-6635512Backup target
Dell EMC XtremIOXIOS4.0.271All-flash array (Gen-1)
HPE Nimble / Nimble AlletraNimbleOS6.1.3.300-1084694-opt7Hybrid/all-flash array
HPE PrimeraPrimera OS4.6.5.191Tier-1 array
HPE PrimeraPrimera OS4.6.20.65Tier-1 array
HPE 3PAR StoreServ3PAR OS3.2.2.7091Tier-1/2 array — EOL, unresearched
HPE 3PAR StoreServ3PAR OS3.3.2.1594Tier-1/2 array
NetApp FAS (cluster pair)ONTAP9.18.1P11NAS/unified
NetApp FAS (cluster pair)ONTAP9.16.1P62NAS/unified
NetApp FAS (cluster pair)ONTAP9.11.1P202NAS/unified
NetApp FAS (cluster pair)ONTAP9.8P211NAS/unified — past Limited Support
IBM Storwize V7000Spectrum Virtualize7.8.1.112Block storage
IBM Storwize V7000Spectrum Virtualize7.8.1.143Block storage
IBM SAN Volume ControllerSpectrum Virtualize8.2.1.111Storage virtualization
Fleet Total (firmware-confirmed)338 platforms
Coverage gap: Pure FlashArray/FlashBlade (3), Dell PowerMax, PowerStore, Unity, HPE Alletra 9080 (2), Cohesity (5 clusters), Nutanix, VAST (2), Qumulo, Hitachi VSP, IBM FS9500 (2), IBM DS8000 (2, unmanaged), Scality (2) — confirmed present in the estate via device inventory but firmware/microcode was not captured by VisualOne telemetry for the July 14, 2026 collection; no CVE analysis possible without a version string.

Findings, Ranked

1
CVE-2022-0778 — IBM Spectrum Virtualize (Storwize V7000 + SVC)
7.5 HIGH (NVD) Risk: HIGH Not KEV-listed

Observed: Storwize 7.8.1.11 (2) + 7.8.1.14 (3) + SVC 8.2.1.11 (1) 6 devices — all below fix    Affected range: 7.8 / 8.2 / 8.3 / 8.4 / 8.5 branches

Vulnerability Evidence: Public PoC exists (GitHub) and this OpenSSL flaw was broadly exploited across other vendors’ products; not itself on the CISA KEV catalog for this CVE ID NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-0778
Remediation: Update to 7.8.1.15 (Storwize) / 8.2.1.16 (SVC). Vendor advisory: IBM ibm6622017 — https://www.ibm.com/support/pages/ibm-security-advisory
Risk if Unresolved: OpenSSL BN_mod_sqrt() infinite loop (DoS). A public PoC exists — treat as HIGH priority despite the absence of a KEV listing.
2
CVE-2022-31813 — Dell EMC Data Domain (DD OS)
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: DD OS 7.1.0.40-663551 2 devices    Affected range: 7.0 – 7.10 (includes 7.1.0.x)

Vulnerability Evidence: Apache mod_proxy X-Forwarded-* auth-bypass technique is publicly documented (upstream Apache advisory); no DD-specific PoC confirmed NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-31813
Remediation: Correction from an earlier draft: this CVE is addressed under Dell advisory DSA-2023-389 (not DSA-2022-302, which does not reference this CVE) — the same advisory covering CVE-2022-36760 below. Update to 7.12.0.0+ / 7.7.5.20+ (LTS2022) / 7.10.1.10+ (LTS2023) — no 7.1.x point-fix exists. Vendor advisory: Dell DSA-2023-389 — https://www.dell.com/support/kbdoc/en-us/000218619
Risk if Unresolved: DD OS 7.1.0.x is a superseded branch — Dell’s fix requires a full upgrade to a current LTS/GA branch, not an in-branch patch.
3
CVE-2022-31228 — Dell EMC XtremIO (XMS)
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: XIOS 4.0.27 1 device (Gen-1 hardware — presumed never migrated past XMS 6.x; XMS build not independently confirmed)    Affected range: XMS prior to 6.4.0-22

Vulnerability Evidence: Unauthenticated brute-force admin-account takeover; no confirmed public PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-31228
Remediation: Update to XMS 6.4.0-22. Vendor advisory: Dell DSA-2022-145 — https://www.dell.com/support/kbdoc/en-us/000204112
Risk if Unresolved: Dell tracks the fix against XMS version, not XIOS. A device still on XIOS 4.0.27 almost certainly predates the 6.x XMS line — treated as presumed-affected pending direct XMS build confirmation.
4
CVE-2021-26588 — HPE 3PAR StoreServ OS
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: 3PAR OS 3.3.2.159 4 devices — inside the affected range    Affected range (3PAR OS specifically): 3.3.1 – 3.3.2 and 4.0.0 – 4.2.8

Vulnerability Evidence: Unauthenticated, network-exploitable admin-takeover flaw; no public PoC found NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-26588
Remediation: Correction from an earlier draft: NVD’s advisory covers three separate product lines with different version ceilings — 3PAR StoreServ OS (3.3.1–3.3.2, 4.0.0–4.2.8), HPE Primera (4.0.0–4.3.3), and HPE Alletra 9000 (9.3.0–9.4.0). The “4.3.3” ceiling belongs to Primera, not 3PAR. For these 3PAR OS 3.3.2.159 devices, update to above 4.2.8. Vendor advisory: HPE HPESBST04191 — https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbst04191en_us
Risk if Unresolved: A 5th device (3PAR OS 3.2.2.709) predates this advisory’s stated 3PAR floor (3.3.1) and could not be matched to a confirmed CVE — flagged separately as unresearched EOL risk, not a fabricated finding.
5
CVE-2021-38969 — IBM SAN Volume Controller (Spectrum Virtualize)
9.8 CRITICAL (NVD) Risk: CRITICAL

Observed: SVC 8.2.1.11 1 device    Affected range: 8.2 / 8.3 / 8.4

Vulnerability Evidence: Reuse of support-generated credentials → unauthorized remote access; no confirmed public exploitation NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-38969
Remediation: Update to 8.2.1.15. Vendor advisory: IBM ibm6584337 — https://www.ibm.com/support/pages/ibm-security-advisory
6
CVE-2022-36760 — Dell EMC Data Domain (DD OS)
9.0 CRITICAL (NVD) Risk: CRITICAL

Observed: DD OS 7.1.0.40-663551 2 devices    Affected range: 7.0 – 7.11 (includes 7.1.0.x)

Vulnerability Evidence: Apache mod_proxy_ajp request smuggling; public writeups exist NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-36760
Remediation: Update to 7.12.0.0+ / 7.7.5.20+ / 7.10.1.10+ — no 7.1.x point-fix exists. Vendor advisory: Dell DSA-2023-389 — https://www.dell.com/support/kbdoc/en-us/000218619
Risk if Unresolved: Same unpatchable-in-branch situation as CVE-2022-31813.
7
CVE-2019-18578 — Dell EMC XtremIO (XMS)
9.0 CRITICAL (NVD) Risk: CRITICAL

Observed: XIOS 4.0.27 1 device (presumed affected — see note above)    Affected range: XMS prior to 6.3.0

Vulnerability Evidence: Stored XSS; no known active exploitation NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-18578
Remediation: Update to XMS 6.3.0. Vendor advisory: Dell DSA-2019-172 — https://www.dell.com/support/kbdoc/en-us/000001833
8
CVE-2022-43873 — IBM SAN Volume Controller (Spectrum Virtualize)
8.8 HIGH (NVD) Risk: HIGH

Observed: SVC 8.2.1.11 1 device    Affected range: 8.2 – 8.5

Vulnerability Evidence: Authenticated GUI code-execution / privilege escalation; no public PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-43873
Remediation: Update to 8.2.1.17. Vendor advisory: IBM ibm6858047 — https://www.ibm.com/support/pages/ibm-security-advisory
9
CVE-2021-29873 — IBM Spectrum Virtualize (Storwize + SVC)
8.1 HIGH (NVD) Risk: HIGH

Observed: Storwize 7.8.1.11/7.8.1.14 (5) + SVC 8.2.1.11 (1) 6 devices    Affected range: 7.8 / 8.4

Vulnerability Evidence: Restricted-shell escape; requires authentication, no public PoC found NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-29873
Remediation: Update to 7.8.1.x update path / 8.2.1.14. Vendor advisory: IBM ibm6497111 — https://www.ibm.com/support/pages/ibm-security-advisory
10
CVE-2018-25032 — IBM SAN Volume Controller (bundled zlib)
7.5 HIGH (NVD) Risk: HIGH

Observed: SVC 8.2.1.11 1 device    Affected range: up to 8.2.1.15

Vulnerability Evidence: zlib memory-corruption denial of service NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-25032
Remediation: Update to 8.2.1.16. Vendor advisory: IBM ibm6622021 — https://www.ibm.com/support/pages/ibm-security-advisory
11
CVE-2022-39167 — IBM Spectrum Virtualize (Storwize)
5.9 MEDIUM (NVD) Risk: MEDIUM

Observed: Storwize 7.8.1.11/7.8.1.14 5 devices    Affected range: 7.8 / 8.2 – 8.5

Vulnerability Evidence: IP Quorum man-in-the-middle information disclosure; MITM position required, no known PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-39167
Remediation: Update to 7.8.1.16. Vendor advisory: IBM ibm6622025 — https://www.ibm.com/support/pages/ibm-security-advisory
12
CVE-2026-22050 — NetApp ONTAP
4.3 MEDIUM (NVD) Risk: MEDIUM

Observed: ONTAP 9.16.1P6 2 cluster pairs    Affected range: 9.16.1 < P9; 9.17.1 < P2

Vulnerability Evidence: Requires privileged access with snapshot locking enabled; no known PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22050
Remediation: Update to 9.16.1P9 / 9.17.1P2. Vendor advisory: NetApp NTAP-20260112-0001 — https://security.netapp.com/advisory/NTAP-20260112-0001
13
CVE-2026-22052 — NetApp ONTAP
4.3 MEDIUM (NVD) Risk: MEDIUM

Observed: ONTAP 9.16.1P6 2 cluster pairs    Affected range: 9.12.1+ , unpatched below 9.16.1P8

Vulnerability Evidence: Requires authenticated attacker + S3 NAS buckets in use; no known PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-22052
Remediation: Update to 9.16.1P8 (or 9.12.1P20/9.13.1P19/9.14.1P16/9.15.1P16/9.17.1P1/9.18.1+). Vendor advisory: NetApp NTAP-20260304-0001 — https://security.netapp.com/advisory/NTAP-20260304-0001
3

Virtual Compute Servers

Every ESXi host and vCenter instance in the estate reports the same version label — a homogeneity that makes a single unpatched build a fleet-wide finding rather than an isolated one.

Estate Inventory

PlatformFirmware / VersionScope
VMware vCenter Server / ESXi8.0.3 (branch label)6 vCenter instances managing 556 ESXi hosts
IBM Power (HMC-managed)CEC firmware 01EL340:75 (Power6 family)1 HMC console 8 managed hosts
IBM Power (HMC-managed)CEC firmware 01AM780:100 (Power7 family)1 HMC console 2 managed hosts
IBM Power (HMC-managed)CEC firmware 01AL730:127 (Power7 family)1 HMC console 21 managed hosts
IBM Power (HMC-managed)CEC firmware 01VM950:194 (Power9 family)1 HMC console 7 managed hosts
IBM Power (HMC-managed)CEC firmware not captured5 HMC consoles 25 managed hosts
Methodology Note — VMware Version Precision

VisualOne’s reported value of “8.0.3” is the ESXi/vCenter 8.0 Update 3 branch label, not a build number. Broadcom’s build strings within this branch (e.g. ESXi_8.0.3-0.73.24784735 for update 3f) span roughly three years of releases, during which the KEV-listed and Critical CVEs below were patched at different points. The findings below should be read as “the estate is somewhere in this branch and must be checked against every fix level,” not as a confirmed-exposed verdict. Recommend pulling esxcli system version get per host and the vCenter build number per instance as the first remediation step.

Findings, Ranked

1
CVE-2024-37079 — VMware / Broadcom vCenter Server
9.8 CRITICAL (NVD) Risk: CRITICAL KEV-listed 2026-01-23

Observed: vCenter 8.0.3 branch label across 6 vCenter instances — likely already past this fix (8.0U2d predates the 8.0U3 branch numerically) but not directly confirmed    Affected range: 8.0 before 8.0U2d / 8.0U1e; 7.0 before 7.0U3r

Vulnerability Evidence: Confirmed in-the-wild unauthenticated RCE NVD: https://nvd.nist.gov/vuln/detail/cve-2024-37079
Remediation: Update to vCenter 8.0U2d. Vendor advisory: VMSA-2024-0012 — https://support.broadcom.com/security-advisories
Risk if Unresolved: Almost certainly already remediated on any genuine 8.0U3 build, but confirm the exact build string rather than assume.
2
CVE-2025-22224 — VMware / Broadcom ESXi
9.3 CRITICAL (VMware) / 8.2 (NVD) (VMware / NVD) Risk: CRITICAL KEV-listed 2025-03-04

Observed: ESXi 8.0.3 branch label reported across all 556 hosts — exact build unconfirmed    Affected range: ESXi 8.0 before 8.0U2d-24585300 and 8.0U3d-24585383; 7.0 before 70U3s

Vulnerability Evidence: Active ransomware exploitation confirmed by CISA (VMX TOCTOU heap overflow) NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-22224
Remediation: Update to ESXi80U3d (build 24585383) or later. Vendor advisory: VMSA-2025-0004 — https://support.broadcom.com/security-advisories
Risk if Unresolved: “8.0.3” is a branch label, not a build number — it cannot by itself confirm patch status. Every host must be checked against build 24585383+.
3
CVE-2025-22225 — VMware / Broadcom ESXi
8.2 HIGH (VMware / NVD — no vendor/NVD scoring split for this CVE) Risk: HIGH KEV-listed 2025-03-04

Observed: ESXi 8.0.3 branch label — exact build unconfirmed    Affected range: Same range as CVE-2025-22224    Correction from an earlier draft: this CVE’s device line previously showed “9.3 CRITICAL” — that score belongs to sibling CVE-2025-22224. VMware’s own rating for CVE-2025-22225 is 8.2, matching NVD.

Vulnerability Evidence: Active in-the-wild exploitation since ~Feb 2024 per CISA (arbitrary write to VMX) NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-22225
Remediation: Update to ESXi80U3d (build 24585383) or later. Vendor advisory: VMSA-2025-0004 — https://support.broadcom.com/security-advisories
4
CVE-2025-41236 — VMware / Broadcom ESXi
9.3 CRITICAL (VMware) Risk: CRITICAL

Observed: ESXi 8.0.3 branch label — exact build unconfirmed    Affected range: Before ESXi80U3f (build 24784735)

Vulnerability Evidence: VMXNET3 virtual NIC integer overflow → guest-to-host RCE (VM escape); no known active exploitation reported NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-41236
Remediation: Update to ESXi80U3f. Vendor advisory: VMSA-2025-0013 — https://support.broadcom.com/security-advisories
5
CVE-2025-41237 — VMware / Broadcom ESXi
9.3 CRITICAL (VMware) Risk: CRITICAL

Observed: ESXi 8.0.3 branch label — exact build unconfirmed    Affected range: Before ESXi80U3f (build 24784735)

Vulnerability Evidence: VMCI integer underflow → out-of-bounds write (VM escape); no known active exploitation reported NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-41237
Remediation: Update to ESXi80U3f. Vendor advisory: VMSA-2025-0013 — https://support.broadcom.com/security-advisories
6
CVE-2025-41238 — VMware / Broadcom ESXi
9.3 CRITICAL (VMware) Risk: CRITICAL

Observed: ESXi 8.0.3 branch label — exact build unconfirmed    Affected range: Before ESXi80U3f (build 24784735)

Vulnerability Evidence: PVSCSI virtual controller heap overflow (VM escape); no known active exploitation reported NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-41238
Remediation: Update to ESXi80U3f. Vendor advisory: VMSA-2025-0013 — https://support.broadcom.com/security-advisories
7
CVE-2025-41225 — VMware / Broadcom vCenter Server
8.8 HIGH (VMware) Risk: HIGH

Observed: vCenter 8.0.3 branch label — exact build unconfirmed    Affected range: Before 8.0U3e (build 24674346)

Vulnerability Evidence: Authenticated command execution (CWE-78); no known active exploitation reported NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-41225
Remediation: Update to vCenter 8.0U3e. Vendor advisory: VMSA-2025-0010 — https://support.broadcom.com/security-advisories
EOL
IBM Power CEC firmware families are past vendor support
Compliance finding Risk: HIGH

Four named CEC firmware families run across 9 HMC-managed environments: 01EL340 (Power6 — support ended ~2016), 01AM780 / 01AL730 (Power7 — support ended ~2020–2021), and 01VM950 (Power9 E950/FW950 — minimum-supported HMC line V9 withdrawn 2023-04-30; next-gen HMC V10.2.x withdrawn 2025-04-30).

Vulnerability Evidence: No vendor security patch exists for the Power6/Power7 firmware families regardless of any future CVE disclosure. Candidate current-generation HMC CVEs to check once the appliance release is confirmed: CVE-2025-1951 (CVSS 8.4) and CVE-2025-1950 — neither is KEV-listed as of 2026-07-15.
Remediation: Run lshmc -V on each HMC console to confirm the actual appliance release, then plan hardware refresh for the Power6/Power7 population.
Risk if Unresolved: An EOL system-firmware family cannot receive a fix even for a Critical, actively-exploited vulnerability — this risk compounds as new Power/PowerVM CVEs are disclosed against currently-supported branches.
4

Virtual Machine Security

Because enterprise_virtual_all_vms_proc timed out at this estate’s scale (one vCenter alone reports 1,956 VMs), this section is sourced directly from VisualOne’s raw per-vCenter export files for July 14, 2026 — 4,914 VM records across 6 vCenters.

361
VMs — No VMware Tools
Zero patch-status visibility (7.3% of estate)
1,818
VMs — Tools Unmanaged
Patch status unknown, not actively tracked
567
VMs on EOL Guest OS
No further vendor security patches available
211
VMs w/ Active Snapshots
Size/age not captured in this export — flagged for follow-up
4,914
Total VMs Analyzed
Across 6 vCenters, raw-export cross-reference
44.3%
VMs Without Current Tools
Unmanaged + Need-Upgrade + Not-Installed combined

VM Estate by vCenter

vCenterVMsVMware Tools BreakdownActive SnapshotsEOL Guest OS
SwissLogvCenter21 Unmanaged / 1 Current00
na97vctr801_gvl9138 Need-Upgrade / 28 Unmanaged / 19 Current / 6 Not-Installed101
s0adcvsphere6.acmewidget.corp7458 Unmanaged / 8 Current / 7 Need-Upgrade / 1 Not-Installed193
qtsvcsa02.acmewidget.corp1134706 Unmanaged / 315 Current / 101 Need-Upgrade / 12 Not-Installed5960
SAL_Secure_vCenter16011,034 Current / 274 Unmanaged / 186 Need-Upgrade / 107 Not-Installed7065
GVL_Secure_vCenter2012751 Unmanaged / 685 Current / 340 Need-Upgrade / 235 Not-Installed53438
Fleet Total4,9142,062 Current / 1,818 Unmanaged / 672 Need-Upgrade / 361 Not-Installed211567
Standout Finding — Security Infrastructure Itself at Risk

Cisco_ISE-02 and Cisco_ISE-03 — Cisco Identity Services Engine, the RADIUS/network-access-control platform gating admission to the network — run on vmx-08, the oldest virtual hardware version found anywhere in the VM estate, on an end-of-life RHEL 6 guest OS, in the qtsvcsa02.acmewidget.corp vCenter. The access-control system itself is the least-current asset in its own environment.

Notable Individual Findings

1
Compound-risk VM stacks four exposure factors simultaneously
na97vctr801_gvl Risk: HIGH

gvx0lcpef30p is powered on and simultaneously: running EOL guest OS (RHEL 6, EOL Nov 2020), on an outdated virtual hardware version (vmx-11), reporting guestToolsUnmanaged, and carrying an active, unresolved snapshot.

Vulnerability Evidence: Any one of these four factors alone would justify a finding; found together on one live, powered-on host, they compound — an EOL kernel with unknown patch state, no live Tools telemetry, and a stale snapshot that could reintroduce a vulnerable state on rollback.
Remediation: Prioritize for OS upgrade or decommission; consolidate/remove the snapshot; reinstall/re-register VMware Tools.
2
Production orchestration host has zero Tools management channel
qtsvcsa02.acmewidget.corp Risk: HIGH

orchestration01.acmewidget.corp, powered on, Ubuntu 64-bit, reports guestToolsNotInstalled — no patch-status visibility into a running, apparently business-critical host.

Vulnerability Evidence: No VMware Tools means no guest-level telemetry (IP, running processes via API, quiesced snapshots) and typically indicates the guest OS itself has not been centrally patch-managed either.
Remediation: Install and register VMware Tools (or open-vm-tools for Linux); confirm patch cadence for the guest OS separately since Tools absence usually correlates with unmanaged OS patching.
3
EOL Windows Server 2003/2000 instances still powered on in production
GVL_Secure_vCenter & SAL_Secure_vCenter Risk: HIGH

GVL_Secure_vCenter contains n0adcmeritem1_NEW (Windows Server 2003 Standard, 32-bit — EOL since 2015, the oldest guest OS found in the estate). SAL_Secure_vCenter separately hosts flsqlc01 (Windows Server 2003, 64-bit, powered on) and a Windows 2000 Server instance.

Vulnerability Evidence: These OS families have received zero security patches for 8-20+ years; any network-reachable service on these hosts is an open door with no vendor remediation path.
Remediation: Isolate on a dedicated VLAN with strict ACLs at minimum; prioritize for migration or decommission.
Data-quality note: Snapshot age and size (num_snapshots/snapshot_size) were not reliably populated in this export — every occurrence found was 0 even where has_snapshot: true. Snapshot counts above reflect presence only; recommend a direct vCenter Snapshot Manager pull to quantify age/size risk on the 211 flagged VMs.
5

Backup Infrastructure — IBM Spectrum Protect

Six IBM Spectrum Protect (TSM) backup servers were cross-referenced against their raw administrative CLI output (query system, query node, query replserver, and related commands) for authentication hardening, node credential hygiene, and inter-server trust configuration.

981
Unlocked Node Credentials
of 989 total (99.2% fleet-wide)
1
EOL Server Version
tsm03 — Spectrum Protect 7.1.3.0 (2017)
6 / 6
Servers, Zero Password Complexity
No alphabetic/upper/lower/numeric/special minimums anywhere
2
Servers — Password Never Expires
tsm03 & NA941004-SAL, 9,999-day expiration period
5 / 6
Servers — Plaintext Replication
No SSL port configured for DB/data replication
6.9 yrs
Oldest Dormant Active Credential
VM__LOCAL_MP_WIN3_MP_LNX on NA941004-SAL

Node Credential Lock Status, Full Fleet

ServerLockedUnlocked% UnlockedOldest Dormant Node (days)
lab10100%*547 (only node; locked)
tsm03022100%1,400 (DONOTDELETE_GVX0WEPPD02S)
NA941004-SAL532098.5%2,511 (VM__LOCAL_MP_WIN3_MP_LNX)
NA941005-SAL0164100%537 (NA940587-SAL)
tsm100276100%582 (VM9-SPDM009-GVL-LOCAL-MP-WIN_MP_LNX)
tsm11219999.0%826 (VE_LNX_VCS0ADCVSPHERE6)
Fleet Total898199.2%2,511 days (~6.9 years)
*lab10 has only 1 registered node total (already locked) — a near-empty instance, not representative of fleet risk. Fleet percentage above excludes lab10 from the denominator context but includes it in the raw sums.

Findings, Ranked

1
tsm03 running an end-of-life server version with authentication controls effectively disabled
tsm03 Risk: CRITICAL

Server is on Spectrum Protect v7.1.3.0 (dated 2017-06-21 per version history) — the 7.1.x line has been out of IBM support for years, superseded by 8.1 in 2016. On top of that: Password Expiration Period = 9,999 days (~27 years, effectively disabled), Invalid Sign-on Attempt Limit = 0 (no account lockout), Minimum Password Length = 0 (no minimum at all).

Vulnerability Evidence: query system output, ANS8000I ‘query system’ / Q STATUS block — Version 7, Release 1, Level 3.0; Password Expiration Period: 9,999 Day(s); Invalid Sign-on Attempt Limit: 0; Minimum Password Length: 0.
Remediation: Upgrade to a currently-supported Spectrum Protect release; set password expiration to 90 days, sign-on limit to 5, minimum length to 8 — matching the configuration already in place on 4 of the other 5 servers.
Risk if Unresolved: An EOL server with no lockout and no minimum password length is trivially brute-forceable and receives no further vendor security patches.
2
99.2% of backup-client node credentials fleet-wide are unlocked, including multi-year-dormant accounts
Fleet-wide Risk: CRITICAL

981 of 989 registered backup-client nodes across the 6-server fleet are unlocked — including a node dormant for 2,511 days (~6.9 years, NA941004-SAL) and another dormant 1,400 days (~3.8 years, tsm03, literally named DONOTDELETE_GVX0WEPPD02S).

Vulnerability Evidence: query node format=detail output across all 6 servers — Locked?: No on 981 of 988 total nodes (excluding the near-empty lab10 instance).
Remediation: Bulk-lock any node with >180 days since last access; establish a quarterly review of node dormancy with automatic locking.
Risk if Unresolved: Each unlocked, unused node credential is a standing, unmonitored authentication path into backup data with no compensating control.
3
Zero password-complexity enforcement fleet-wide
All 6 servers Risk: HIGH

Minimum Password Alphabetic/Uppercase/Lowercase/Numeric/Special-Character requirements are all set to 0 on every one of the 6 servers — only password length and expiration period vary server-to-server.

Vulnerability Evidence: query system Q STATUS block, identical zero values across lab10, tsm03, NA941004-SAL, NA941005-SAL, tsm10, tsm11.
Remediation: Set minimum complexity requirements (at least 1 uppercase, 1 numeric, 1 special character) consistent with organizational password policy.
4
Inter-server replication rides plaintext TCP on 5 of 6 servers
lab10, NA941004-SAL, NA941005-SAL, tsm10, tsm11 Risk: MEDIUM

Only tsm03 has an SSL failover port configured (1542) for server-to-server replication; the other 5 servers show a blank SSL port on every replication peer definition, meaning database/data replication traffic rides plaintext TCP port 1500. Inter-server administrative peer-password hygiene is also inconsistent: lab10 and NA941005-SAL have 0 of their peer definitions password-protected, while tsm03 has all 9 of its peers password-protected (but zero of them use SSL).

Vulnerability Evidence: query replserver output across all 6 servers — SSL port field blank except tsm03.
Remediation: Enable SSL for all inter-server replication links; set a password on every peer server definition, prioritizing lab10 and NA941005-SAL.
6

Hidden Security Gems

Ten findings surfaced only by cross-referencing raw vendor export data — IBM Spectrum Protect CLI output, VMware vCenter exports, and HP Primera array output — from Y:\Temp Download\RBS\July 14, ranked by severity. None of these are visible from aggregate VOI telemetry alone; each required reading the underlying raw fields.

1
IBM Spectrum Protect server tsm03 running EOL v7.1.3.0 with authentication effectively disabled
Source: TSM_BACKUP-0714260203_tsm03 / TSMOUTFILE_SYSTEM.TXT CRIT
Evidence: Version 7, Release 1, Level 3.0 (dated 2017-06-21); Password Expiration Period: 9,999 Day(s); Invalid Sign-on Attempt Limit: 0; Minimum Password Length: 0.
Action: Upgrade server to a supported release; align auth policy (90-day expiration, 5-attempt lockout, 8-char minimum) with the other 5 servers.
Risk: EOL, unpatched server with no lockout and no minimum password length is trivially brute-forceable.
2
99.3% of backup-client node credentials fleet-wide are unlocked, including a 6.9-year-dormant account
Source: All 6 TSM_BACKUP folders / TSMOUTFILE_NODE.TXT CRIT
Evidence: 981 of 988 registered nodes show Locked?: No; oldest dormant unlocked node (VM__LOCAL_MP_WIN3_MP_LNX, NA941004-SAL) last accessed 2,511 days ago.
Action: Bulk-lock nodes dormant >180 days; institute quarterly dormancy review.
Risk: Standing, unmonitored authentication paths into backup data and restore operations.
3
Cisco ISE (network access control) runs on the oldest virtual hardware version in the VM estate with an EOL guest OS
Source: VMWARE_DEVICE-0714260200_qtsvcsa02_dc01_peapod_com / VMWARE_DEVICE_COMPARISON_output.jsn HIGH
Evidence: Cisco_ISE-02 and Cisco_ISE-03 report model: “vmx-08” (oldest in the estate) and os_name indicating RHEL 6 (EOL Nov 2020).
Action: Upgrade virtual hardware version and guest OS on both ISE nodes as a priority — this is authentication/NAC infrastructure, not a general-purpose workload.
Risk: The system gating network admission is itself running unsupported, unpatched software.
4
361 VMs estate-wide have zero VMware Tools installed — no patch-status visibility
Source: All 6 VMWARE_DEVICE_COMPARISON_output.jsn files HIGH
Evidence: tools_version_status: “guestToolsNotInstalled” on 361 of 4,914 VM records, including live production hosts (e.g. orchestration01.node.fdln.acmewidget.corp).
Action: Install/register VMware Tools on all affected guests; prioritize powered-on production hosts first.
Risk: No guest-level telemetry means no reliable way to confirm patch state or respond to an incident inside these guests.
5
567 VMs run an end-of-life guest operating system with no further vendor security patches
Source: All 6 VMWARE_DEVICE_COMPARISON_output.jsn files HIGH
Evidence: Includes Windows Server 2003 (10), Windows 2000 Server (1), Windows Server 2008/2008R2 (100+), Windows 7 (11), and 290+ RHEL 6 instances concentrated in GVL_Secure_vCenter.
Action: Inventory and prioritize migration/decommission plan for EOL-OS hosts; isolate on restricted VLANs as an interim control.
Risk: No vendor remediation path exists for any future vulnerability discovered in these OS families.
6
Zero password-complexity requirements enforced across all 6 IBM Spectrum Protect servers
Source: All 6 TSM_BACKUP folders / TSMOUTFILE_SYSTEM.TXT HIGH
Evidence: Minimum Password Alphabetic/Uppercase/Lowercase/Numeric/Special Characters: 0 on every server, uniformly.
Action: Set minimum complexity requirements consistent with organizational password policy.
Risk: Length-only policies are materially weaker against credential-stuffing and dictionary attacks.
7
Inter-server backup replication traffic is unencrypted on 5 of 6 Spectrum Protect servers
Source: All 6 TSM_BACKUP folders / TSMOUTFILE_REPLSERVER.TXT MED
Evidence: SSL failover port is blank on every replication peer definition except tsm03 (port 1542); replication rides plaintext TCP 1500 elsewhere.
Action: Enable SSL for all inter-server replication links fleet-wide.
Risk: Backup metadata and control-plane traffic between servers is exposed to network-level interception.
8
HP Primera fleet: remote syslog forwarding enabled with mutual TLS but destination host unset on all 5 arrays
Source: All 5 HP_PRIMERA_DEVICE-* folders / HP_PRIMERA_DEVICE_output.jsn MED
Evidence: remoteSyslogEnableMutualTLS: true and remoteSyslogHost: “0.0.0.0” identically on all 5 arrays (NA01SOB-SN00ZV/012P/03G8/044V/07G3).
Action: Configure an actual remote syslog/SIEM destination host on all 5 arrays; the security control is enabled but not functionally shipping any logs.
Risk: Security-relevant array events are not being centrally logged or monitored despite appearing ‘configured’ at a glance.
9
A single VM stacks four separate security-relevant exposure factors simultaneously
Source: VMWARE_DEVICE-0714260206_na97vctr801_gvl / VMWARE_DEVICE_COMPARISON_output.jsn MED
Evidence: gvx0lcpef30p: powered on, EOL guest OS (RHEL 6), outdated virtual hardware (vmx-11), guestToolsUnmanaged, and an active unresolved snapshot — all four factors on one live host.
Action: Prioritize for OS upgrade or decommission; remove the stale snapshot; reinstall VMware Tools.
Risk: A single-dimension scan (checking only OS, or only Tools, or only snapshots) would under-rank this host; the compounding effect is only visible cross-referencing all fields together.
10
Broad VM-backup proxy-node authorization scoping compounds the unlocked-node risk
Source: 4 of 6 TSM_BACKUP folders / TSMOUTFILE_PROXYNODE.TXT MED
Evidence: NA941004-SAL, NA941005-SAL, tsm10, and tsm11 each authorize dozens of Agent Nodes (6-8 per Target Node) for VMware-VE backup data movement.
Action: Audit proxy-node scoping and tighten to least-privilege groupings; prioritize alongside the node-lockout remediation (#2) since a compromised VMCLI credential can act across many downstream VM groups.
Risk: A single compromised proxy credential can impersonate or restore data across many VM groups, multiplying the impact of the unlocked-node population.
7

SAN Switches

Sixteen of 25 fabric switches reported firmware in this collection — 12 Brocade and 4 Cisco MDS — and 12 of those 16 carry a confirmed applicable CVE.

Estate Inventory — Firmware Confirmed

VendorProductFabric OS / NX-OS VersionSwitches
BrocadeFabric OSv9.2.1a2
BrocadeFabric OSv9.2.1b2
BrocadeFabric OSv8.2.3e22
BrocadeFabric OSv8.2.2d6
Cisco MDS 9000NX-OS8.3(2)4
Fleet Total (firmware-confirmed)16
Coverage gap: 9 of the fabric’s 21 named Brocade switches (per the VisualOne device catalog) did not report a firmware string in the July 14, 2026 collection — inventory-confirmed, version-unconfirmed. Cisco MDS CVE coverage for NX-OS 8.3(2) could not be fully resolved against Cisco’s Software Checker in this pass (see Methodology).

Findings, Ranked

1
CVE-2024-5461 — Broadcom / Brocade Fabric OS
8.6 HIGH (NVD v4.0) / 8.0 (v3.1) (NVD) Risk: HIGH

Observed: FOS v8.2.2d 6 switches — inside affected range (v8.2.3e2 already past fix)    Affected range: Before 8.2.3e1

Vulnerability Evidence: Requires SNMP enabled on Brocade 6547 / FC5022 embedded blade specifically; authenticated attacker → root command injection; no known active exploitation NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-5461
Remediation: Update to 8.2.3e1+. Vendor advisory: Broadcom BSA (FOS 8.2.3x disclosures) — https://support.broadcom.com/security-advisories
Risk if Unresolved: Confirm whether SNMP is enabled on the affected blades before treating as live — but the version gap itself is the actionable finding.
2
CVE-2025-58382 — Broadcom / Brocade Fabric OS
8.5 HIGH (NVD v4.0) / 7.2 (v3.1) (NVD) Risk: HIGH

Observed: FOS v9.2.1a (2) + v9.2.1b (2) 4 switches — below fix    Affected range: Before 9.2.1c2; 9.2.2 – 9.2.2a

Vulnerability Evidence: Requires authenticated admin credentials via supportsave/seccertmgmt/configupload; no public PoC known NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-58382
Remediation: Update to 9.2.1c2 / 9.2.2b. Vendor advisory: Broadcom BSA (FOS 9.2.x disclosures) — https://support.broadcom.com/security-advisories
3
CVE-2026-0383 — Broadcom / Brocade Fabric OS
8.2 HIGH (NVD v4.0) / 7.8 (v3.1) (NVD) Risk: HIGH

Observed: FOS v9.2.1a (2) + v9.2.1b (2) 4 switches — below fix    Affected range: Before 9.2.1c2; 9.2.2 – 9.2.2a; 10.0.0

Vulnerability Evidence: Local bash-shell access required; published 2026-02-02, no known PoC NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-0383
Remediation: Update to 9.2.1c2 / 9.2.2b / 10.0.0a. Vendor advisory: Broadcom BSA (FOS 9.2.x disclosures) — https://support.broadcom.com/security-advisories
4
CVE-2024-7517 — Broadcom / Brocade Fabric OS
7.8 HIGH (NVD v3.1) / 8.5 (v4.0) (NVD) Risk: HIGH

Observed: FOS v9.2.1a 2 switches — inside affected range (v9.2.1b already past fix)    Affected range: Before 9.2.0c; 9.2.1 – 9.2.1a

Vulnerability Evidence: Only exploitable on IP-extension platforms (7810/7840/7850, X6/X7 with SX-6 blade) with SSH/console access — confirm platform applicability NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-7517
Remediation: Update to 9.2.0c / 9.2.1a1. Vendor advisory: Broadcom BSA (FOS 9.2.x disclosures) — https://support.broadcom.com/security-advisories
5
CVE-2024-10403 — Broadcom / Brocade Fabric OS
7.5 HIGH (NVD) Risk: HIGH

Observed: FOS v9.2.1a (2) + v8.2.2d (6) 8 switches — inside affected range    Affected range: Before 8.2.3e2; 9.0.0 – 9.2.0c; 9.2.1 – 9.2.1a

Vulnerability Evidence: Passive: credential exposure via SANnav/WebEM core dump captured in SupportSave; no active-exploit reports NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-10403
Remediation: Update to 8.2.3e2 / 9.2.1a1+. Vendor advisory: Broadcom BSA advisory 25145 — https://support.broadcom.com/security-advisories
Risk if Unresolved: Already remediated on the fabric’s v8.2.3e2 and v9.2.1b switches — a concrete, CVE-backed illustration of the fabric’s patching gap.
Patching Discipline

Six switches run Fabric OS v8.2.2d — the single oldest firmware train in the estate. CVE-2024-5461 and CVE-2024-10403 are open on every v8.2.2d switch and already closed on the v8.2.3e2 pair in the same fabric — an active, CVE-confirmed patch gap on 75% of the estate’s 8.2.x population.

8

Remediation Plan

Ranked by impact (CVSS/severity × KEV or active-exploitation status × effort). The KEV-driven and backup-authentication items lead the plan — VMware build verification, the tsm03 EOL/auth rebuild, and the fleet-wide node-lockout cleanup deliver the largest risk reduction relative to effort.

#ActionGroupPriorityDriving CVEs
1Confirm exact ESXi/vCenter build string on all 556 hosts + 6 vCentersVirtualCRITCVE-2025-22224/22225/2024-37079 (KEV)
2Upgrade tsm03 off EOL Spectrum Protect v7.1.3.0; enable lockout/min password lengthBackupCRITHidden Gem #1
3Bulk-lock dormant (>180d) backup-client nodes fleet-wide (981 unlocked)BackupCRITHidden Gem #2
4Patch IBM Storwize V7000 (5) + SVC (1) past 7.8.1.15 / 8.2.1.17StorageCRITCVE-2022-0778, CVE-2021-38969, CVE-2022-43873
5Upgrade HPE 3PAR OS 3.3.2.159 fleet (4 devices) above 4.3.3StorageCRITCVE-2021-26588
6Plan Dell EMC Data Domain major-version upgrade off DD OS 7.1.x (2 devices)StorageCRITCVE-2022-31813, CVE-2022-36760 — no in-branch fix exists
7Confirm XtremIO XMS build; upgrade past 6.4.0-22 (1 device)StorageCRITCVE-2022-31228, CVE-2019-18578
8Upgrade Cisco ISE nodes off vmx-08/RHEL6 — network access control infrastructureVirtualHIGHHidden Gem #3
9Remediate 361 VMs with guestToolsNotInstalled; prioritize powered-on hostsVirtualHIGHHidden Gem #4
10Plan migration/decommission for 567 VMs on EOL guest OS (2003/2008/2000/RHEL6)VirtualHIGHHidden Gem #5
11Enforce password complexity requirements on all 6 Spectrum Protect serversBackupHIGHHidden Gem #6
12Patch Brocade v8.2.2d switches (6) to 8.2.3e1+SAN SwitchHIGHCVE-2024-5461, CVE-2024-10403
13Patch Brocade v9.2.1a/b switches (4) to 9.2.1c2+SAN SwitchHIGHCVE-2025-58382, CVE-2026-0383, CVE-2024-7517
14Enable SSL for inter-server Spectrum Protect replication (5 of 6 servers plaintext)BackupMEDHidden Gem #7
15Configure a real remote syslog destination on all 5 HP Primera arraysStorageMEDHidden Gem #8
16Run Cisco Software Checker against NX-OS 8.3(2) (4 switches)SAN SwitchMEDCoverage gap — no confirmed CVE yet
17Verify HPE 3PAR OS 3.2.2.709 support status; plan refresh (1 device)StorageMEDEOL, unresearched — no confirmed CVE
18Standardize NetApp ONTAP fleet; retire 9.8P21 (past Limited Support)StorageMEDCVE-2026-22050/22052; EOL compliance
19Confirm HMC appliance release (lshmc -V); plan Power6/7 refreshVirtualHIGHEOL — no vendor patch path
20Audit and tighten TSM VM-backup proxy-node scopingBackupMEDHidden Gem #10
9

Methodology & Caveats

Every finding in this report traces to a live query or a named raw-data file on the date below. Nothing here is inferred without disclosure, and no CVE ID was invented.

Inventory Source

Visual One Intelligence (VisualOne), client ACME Widget, collection date July 14, 2026 (internally tracked as period_id 4213, with several bulk procs returning a mixed 4213/4214 rolling window through July 15, 2026). Correction from initial request: period_id 1413 — the value initially supplied for this engagement — resolves to a Fabric-OS-context-only period dated January 17, 2026, not July 14, and returns empty result sets for the Storage, Device, and Virtual contexts entirely. Period_id 4213 was identified as the correct cross-context period for July 14, 2026 and used throughout this report.

Procs queried: enterprise_devices_proc, enterprise_storage_all_devices_proc, enterprise_switch_proc, enterprise_virtual_summary_proc, visualone_list_units (devices/switches/esx_hosts). enterprise_virtual_all_vms_proc was attempted for VM-level detail but timed out at this estate’s scale (single vCenters reporting 1,000+ VMs) — Section 04 (Virtual Machine Security) is sourced from raw per-vCenter export files instead (see below).

Raw Data Sources (Sections 04–06)

Directory: Y:\Temp Download\RBS\July 14. VMware: 6 VMWARE_DEVICE_COMPARISON_output.jsn exports (2MB–731MB; the two largest were processed via streaming grep extraction only, never loaded in full, to avoid memory/context limits), covering 4,914 VM records across 6 vCenters. Backup: 6 TSM_BACKUP-* folders, each containing ~30 IBM Spectrum Protect CLI output files (query system, query node, query replserver, query proxynode, and related commands). Storage: 5 HP_PRIMERA_DEVICE-* raw JSON exports (2MB–47MB) cross-referenced for encryption and remote-logging configuration.

Vulnerability Feeds Queried (query date July 15, 2026)

Tier 1: CISA KEV catalog, NVD, CVE.org. EUVD, OSV.dev, and VulnCheck NVD++ were considered but did not surface additional confirmed findings beyond NVD/CVE.org for this inventory.
Vendor PSIRT: Dell Security Advisories (DSA), HPE Security Bulletin Library, NetApp Security Advisories (NTAP-), IBM Security Advisories, Broadcom/Brocade Security Advisories, Cisco PSIRT openVuln.
Vendor corpus: remote qdrant-storage MCP (SSE transport) — queried for every vendor; returned indexed content for VMware vSphere and NetApp ONTAP product documentation only; did not contain PSIRT-indexed CVE text for Dell Data Domain/XtremIO, Brocade, or Cisco.

Known Coverage Gaps

  • Storage: 21 additional storage devices confirmed present via the VisualOne device catalog (Pure FlashArray/FlashBlade, Dell PowerMax/PowerStore/Unity, HPE Alletra 9080, Cohesity, Nutanix, VAST, Qumulo, Hitachi VSP, IBM FS9500/DS8000, Scality) did not return a firmware/microcode string in the July 14, 2026 collection — inventoried, not CVE-analyzed.
  • SAN Switches: 9 of 21 named Brocade switches did not return a firmware string this period. Cisco NX-OS 8.3(2) CVE applicability could not be fully resolved without querying Cisco’s Software Checker tool directly against the exact build string.
  • Virtual Compute: VisualOne reports VMware version as the “8.0.3” update-branch label, not a build number — see the callout in Section 03. 5 of 9 IBM Power HMC consoles did not return a CEC firmware string this period.
  • Virtual Machine Security: Per-VM snapshot age/size fields (num_snapshots/snapshot_size) were not reliably populated in the raw VMware export — presence of a snapshot could be confirmed, but not its age or size, across all 6 vCenters.
  • HPE 3PAR OS 3.2.2.709 (1 device) predates the floor of the one confirmed critical 3PAR advisory in scope; no separate CVE could be verified against this exact build.
  • HPE Nimble/Alletra CVE-2026-23594correction from an earlier draft: this is not a RESERVED/empty CVE record. It is a published vulnerability (CVSS 8.8 HIGH) covered by HPE Security Bulletin HPESBST04995 rev.1 (published 2026-01-20), affecting HPE Alletra 6000/5000 and Nimble Storage (Hybrid Flash/All Flash), with fixed versions 6.1.2.800 and 6.1.3.300. NVD’s own record was still lagging publication at query time. Observed firmware (6.1.3.300) matches one of the two vendor-listed fixed versions, so these devices are not exposed — retained as informational and not counted in headline KPIs, but for the correct reason (already patched, not because the CVE lacks a record).

KEV Catalog Version

CISA KEV catalog as queried live on July 15, 2026. No formal catalog-version/build number is published by CISA; queries were run against the live catalog search interface on the stated date.

Post-Publication Fact-Check (July 15, 2026)

A subsequent independent verification pass re-checked every CVE in this report against NVD, CVE.org, CISA KEV, and vendor advisory pages, and corrected five errors found in the original draft: (1) CVE-2022-0778 was incorrectly marked KEV-listed — it is not on the CISA KEV catalog, and the “2022-03-15” date was OpenSSL’s patch-release date, not a KEV addition date; the KEV-listed CVE count was corrected from 4 to 3 and headline Critical/High counts adjusted accordingly. (2) CVE-2022-31813 was attributed to the wrong Dell advisory (DSA-2022-302, which does not reference this CVE) with fabricated fix versions; corrected to DSA-2023-389 with fix versions 7.12.0.0+/7.7.5.20+/7.10.1.10+. (3) CVE-2021-26588’s affected-range conflated HPE 3PAR OS and HPE Primera OS version numbering; corrected to the 3PAR-specific range and fix floor. (4) CVE-2025-22225’s device line showed a CVSS score (9.3) that actually belongs to sibling CVE-2025-22224; corrected to 8.2, moving this finding from the Critical to the High bucket. (5) CVE-2026-23594 was described as RESERVED with no live record; it in fact has a published HPE bulletin (HPESBST04995 rev.1, CVSS 8.8) — the report’s conclusion that observed firmware already meets the fixed baseline was correct, but the CVE’s status description was not. Separately, for CVE-2021-38969 and CVE-2022-43873, note that IBM’s own CNA-assigned CVSS scores (5.6 and 6.3 respectively) are substantially lower than the NVD scores cited in this report (9.8 and 8.8); this report cites NVD consistently across all findings, but the vendor/NVD split is disclosed here for completeness. All other CVE IDs, CVSS scores, KEV statuses, and vendor advisory citations in this report were independently confirmed accurate.

Visual One Intelligence Platform    ACME Widget Security Analysis    July 14, 2026    Prepared by Van Symons