Twenty-five CVEs with confirmed NVD or CVE.org records apply to firmware and software actively running across the ACME Widget estate as of the July 14, 2026 collection — 11 Critical, 11 High, 3 Medium — including 3 CVEs on the CISA Known Exploited Vulnerabilities (KEV) catalog.
| Resource Group | Assets in Scope | KEV | Critical | High | Medium |
|---|---|---|---|---|---|
| Storage Arrays | 33 | 0 | 6 | 4 | 3 |
| Virtual Compute Servers | 556 hosts / 6 vCenters + 9 HMC | 3 | 5 | 2 | 0 |
| SAN Switches | 16 | 0 | 0 | 5 | 0 |
| Fleet Total | 33 + 556 hosts + 16 | 3 | 11 | 11 | 3 |
Confirm the exact ESXi/vCenter build string (not the “8.0.3” branch label) on all 556 hosts and 6 vCenter instances. If any host predates ESXi80U3d (build 24585383) or any vCenter predates 8.0U2d, it is exposed to actively-exploited, KEV-listed ransomware vulnerabilities today. See Section 03.
Six devices — two IBM Storwize V7000 pairs and one IBM SAN Volume Controller — carry CVE-2022-0778 (CVSS 7.5, public proof-of-concept exists). Correction from an earlier draft of this report: CVE-2022-0778 is not on the CISA KEV catalog — the March 2022 date associated with it is OpenSSL’s patch-release date, not a KEV addition date; it has been removed from the KEV count below. The three genuinely KEV-listed CVEs in this estate are all VMware/Broadcom vCenter and ESXi vulnerabilities (Section 03). Two Dell EMC Data Domain backup targets run a DD OS branch (7.1.0.x) Dell no longer issues point-fixes for, so two Critical CVEs cannot be remediated without a major-version upgrade. Six Brocade switches sit on the fabric’s oldest firmware train (v8.2.2d) and carry two High-severity CVEs already closed on sibling switches in the same fabric.
Beyond CVE exposure, direct cross-reference of 4,914 VM records (Section 04) and 6 IBM Spectrum Protect backup servers (Section 05) against raw VisualOne export data surfaced 10 additional hidden security gems (Section 06) — most notably a backup server running a 2017-era, unsupported software release with authentication controls effectively disabled, and 981 of 988 backup-client node credentials fleet-wide left unlocked, some dormant for nearly 7 years.
Thirty-three storage devices across 8 platforms reported a firmware or OS version in the July 14, 2026 collection; 13 confirmed CVEs apply across 6 of those platforms.
| Vendor | Product | Observed Firmware | Devices | Role |
|---|---|---|---|---|
| Dell EMC Data Domain | DD OS | 7.1.0.40-663551 | 2 | Backup target |
| Dell EMC XtremIO | XIOS | 4.0.27 | 1 | All-flash array (Gen-1) |
| HPE Nimble / Nimble Alletra | NimbleOS | 6.1.3.300-1084694-opt | 7 | Hybrid/all-flash array |
| HPE Primera | Primera OS | 4.6.5.19 | 1 | Tier-1 array |
| HPE Primera | Primera OS | 4.6.20.6 | 5 | Tier-1 array |
| HPE 3PAR StoreServ | 3PAR OS | 3.2.2.709 | 1 | Tier-1/2 array — EOL, unresearched |
| HPE 3PAR StoreServ | 3PAR OS | 3.3.2.159 | 4 | Tier-1/2 array |
| NetApp FAS (cluster pair) | ONTAP | 9.18.1P1 | 1 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.16.1P6 | 2 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.11.1P20 | 2 | NAS/unified |
| NetApp FAS (cluster pair) | ONTAP | 9.8P21 | 1 | NAS/unified — past Limited Support |
| IBM Storwize V7000 | Spectrum Virtualize | 7.8.1.11 | 2 | Block storage |
| IBM Storwize V7000 | Spectrum Virtualize | 7.8.1.14 | 3 | Block storage |
| IBM SAN Volume Controller | Spectrum Virtualize | 8.2.1.11 | 1 | Storage virtualization |
| Fleet Total (firmware-confirmed) | 33 | 8 platforms | ||
Observed: Storwize 7.8.1.11 (2) + 7.8.1.14 (3) + SVC 8.2.1.11 (1) • 6 devices — all below fix • Affected range: 7.8 / 8.2 / 8.3 / 8.4 / 8.5 branches
Observed: DD OS 7.1.0.40-663551 • 2 devices • Affected range: 7.0 – 7.10 (includes 7.1.0.x)
Observed: XIOS 4.0.27 • 1 device (Gen-1 hardware — presumed never migrated past XMS 6.x; XMS build not independently confirmed) • Affected range: XMS prior to 6.4.0-22
Observed: 3PAR OS 3.3.2.159 • 4 devices — inside the affected range • Affected range (3PAR OS specifically): 3.3.1 – 3.3.2 and 4.0.0 – 4.2.8
Observed: SVC 8.2.1.11 • 1 device • Affected range: 8.2 / 8.3 / 8.4
Observed: DD OS 7.1.0.40-663551 • 2 devices • Affected range: 7.0 – 7.11 (includes 7.1.0.x)
Observed: XIOS 4.0.27 • 1 device (presumed affected — see note above) • Affected range: XMS prior to 6.3.0
Observed: SVC 8.2.1.11 • 1 device • Affected range: 8.2 – 8.5
Observed: Storwize 7.8.1.11/7.8.1.14 (5) + SVC 8.2.1.11 (1) • 6 devices • Affected range: 7.8 / 8.4
Observed: SVC 8.2.1.11 • 1 device • Affected range: up to 8.2.1.15
Observed: Storwize 7.8.1.11/7.8.1.14 • 5 devices • Affected range: 7.8 / 8.2 – 8.5
Observed: ONTAP 9.16.1P6 • 2 cluster pairs • Affected range: 9.16.1 < P9; 9.17.1 < P2
Observed: ONTAP 9.16.1P6 • 2 cluster pairs • Affected range: 9.12.1+ , unpatched below 9.16.1P8
Every ESXi host and vCenter instance in the estate reports the same version label — a homogeneity that makes a single unpatched build a fleet-wide finding rather than an isolated one.
| Platform | Firmware / Version | Scope |
|---|---|---|
| VMware vCenter Server / ESXi | 8.0.3 (branch label) | 6 vCenter instances managing 556 ESXi hosts |
| IBM Power (HMC-managed) | CEC firmware 01EL340:75 (Power6 family) | 1 HMC console • 8 managed hosts |
| IBM Power (HMC-managed) | CEC firmware 01AM780:100 (Power7 family) | 1 HMC console • 2 managed hosts |
| IBM Power (HMC-managed) | CEC firmware 01AL730:127 (Power7 family) | 1 HMC console • 21 managed hosts |
| IBM Power (HMC-managed) | CEC firmware 01VM950:194 (Power9 family) | 1 HMC console • 7 managed hosts |
| IBM Power (HMC-managed) | CEC firmware not captured | 5 HMC consoles • 25 managed hosts |
VisualOne’s reported value of “8.0.3” is the ESXi/vCenter 8.0 Update 3 branch label, not a build number. Broadcom’s build strings within this branch (e.g. ESXi_8.0.3-0.73.24784735 for update 3f) span roughly three years of releases, during which the KEV-listed and Critical CVEs below were patched at different points. The findings below should be read as “the estate is somewhere in this branch and must be checked against every fix level,” not as a confirmed-exposed verdict. Recommend pulling esxcli system version get per host and the vCenter build number per instance as the first remediation step.
Observed: vCenter 8.0.3 branch label across 6 vCenter instances — likely already past this fix (8.0U2d predates the 8.0U3 branch numerically) but not directly confirmed • Affected range: 8.0 before 8.0U2d / 8.0U1e; 7.0 before 7.0U3r
Observed: ESXi 8.0.3 branch label reported across all 556 hosts — exact build unconfirmed • Affected range: ESXi 8.0 before 8.0U2d-24585300 and 8.0U3d-24585383; 7.0 before 70U3s
Observed: ESXi 8.0.3 branch label — exact build unconfirmed • Affected range: Same range as CVE-2025-22224 • Correction from an earlier draft: this CVE’s device line previously showed “9.3 CRITICAL” — that score belongs to sibling CVE-2025-22224. VMware’s own rating for CVE-2025-22225 is 8.2, matching NVD.
Observed: ESXi 8.0.3 branch label — exact build unconfirmed • Affected range: Before ESXi80U3f (build 24784735)
Observed: ESXi 8.0.3 branch label — exact build unconfirmed • Affected range: Before ESXi80U3f (build 24784735)
Observed: ESXi 8.0.3 branch label — exact build unconfirmed • Affected range: Before ESXi80U3f (build 24784735)
Observed: vCenter 8.0.3 branch label — exact build unconfirmed • Affected range: Before 8.0U3e (build 24674346)
Four named CEC firmware families run across 9 HMC-managed environments: 01EL340 (Power6 — support ended ~2016), 01AM780 / 01AL730 (Power7 — support ended ~2020–2021), and 01VM950 (Power9 E950/FW950 — minimum-supported HMC line V9 withdrawn 2023-04-30; next-gen HMC V10.2.x withdrawn 2025-04-30).
lshmc -V on each HMC console to confirm the actual appliance release, then plan hardware refresh for the Power6/Power7 population.Because enterprise_virtual_all_vms_proc timed out at this estate’s scale (one vCenter alone reports 1,956 VMs), this section is sourced directly from VisualOne’s raw per-vCenter export files for July 14, 2026 — 4,914 VM records across 6 vCenters.
| vCenter | VMs | VMware Tools Breakdown | Active Snapshots | EOL Guest OS |
|---|---|---|---|---|
| SwissLogvCenter | 2 | 1 Unmanaged / 1 Current | 0 | 0 |
| na97vctr801_gvl | 91 | 38 Need-Upgrade / 28 Unmanaged / 19 Current / 6 Not-Installed | 10 | 1 |
| s0adcvsphere6.acmewidget.corp | 74 | 58 Unmanaged / 8 Current / 7 Need-Upgrade / 1 Not-Installed | 19 | 3 |
| qtsvcsa02.acmewidget.corp | 1134 | 706 Unmanaged / 315 Current / 101 Need-Upgrade / 12 Not-Installed | 59 | 60 |
| SAL_Secure_vCenter | 1601 | 1,034 Current / 274 Unmanaged / 186 Need-Upgrade / 107 Not-Installed | 70 | 65 |
| GVL_Secure_vCenter | 2012 | 751 Unmanaged / 685 Current / 340 Need-Upgrade / 235 Not-Installed | 53 | 438 |
| Fleet Total | 4,914 | 2,062 Current / 1,818 Unmanaged / 672 Need-Upgrade / 361 Not-Installed | 211 | 567 |
Cisco_ISE-02 and Cisco_ISE-03 — Cisco Identity Services Engine, the RADIUS/network-access-control platform gating admission to the network — run on vmx-08, the oldest virtual hardware version found anywhere in the VM estate, on an end-of-life RHEL 6 guest OS, in the qtsvcsa02.acmewidget.corp vCenter. The access-control system itself is the least-current asset in its own environment.
gvx0lcpef30p is powered on and simultaneously: running EOL guest OS (RHEL 6, EOL Nov 2020), on an outdated virtual hardware version (vmx-11), reporting guestToolsUnmanaged, and carrying an active, unresolved snapshot.
orchestration01.acmewidget.corp, powered on, Ubuntu 64-bit, reports guestToolsNotInstalled — no patch-status visibility into a running, apparently business-critical host.
GVL_Secure_vCenter contains n0adcmeritem1_NEW (Windows Server 2003 Standard, 32-bit — EOL since 2015, the oldest guest OS found in the estate). SAL_Secure_vCenter separately hosts flsqlc01 (Windows Server 2003, 64-bit, powered on) and a Windows 2000 Server instance.
num_snapshots/snapshot_size) were not reliably populated in this export — every occurrence found was 0 even where has_snapshot: true. Snapshot counts above reflect presence only; recommend a direct vCenter Snapshot Manager pull to quantify age/size risk on the 211 flagged VMs.Six IBM Spectrum Protect (TSM) backup servers were cross-referenced against their raw administrative CLI output (query system, query node, query replserver, and related commands) for authentication hardening, node credential hygiene, and inter-server trust configuration.
| Server | Locked | Unlocked | % Unlocked | Oldest Dormant Node (days) |
|---|---|---|---|---|
| lab10 | 1 | 0 | 0%* | 547 (only node; locked) |
| tsm03 | 0 | 22 | 100% | 1,400 (DONOTDELETE_GVX0WEPPD02S) |
| NA941004-SAL | 5 | 320 | 98.5% | 2,511 (VM__LOCAL_MP_WIN3_MP_LNX) |
| NA941005-SAL | 0 | 164 | 100% | 537 (NA940587-SAL) |
| tsm10 | 0 | 276 | 100% | 582 (VM9-SPDM009-GVL-LOCAL-MP-WIN_MP_LNX) |
| tsm11 | 2 | 199 | 99.0% | 826 (VE_LNX_VCS0ADCVSPHERE6) |
| Fleet Total | 8 | 981 | 99.2% | 2,511 days (~6.9 years) |
Server is on Spectrum Protect v7.1.3.0 (dated 2017-06-21 per version history) — the 7.1.x line has been out of IBM support for years, superseded by 8.1 in 2016. On top of that: Password Expiration Period = 9,999 days (~27 years, effectively disabled), Invalid Sign-on Attempt Limit = 0 (no account lockout), Minimum Password Length = 0 (no minimum at all).
981 of 989 registered backup-client nodes across the 6-server fleet are unlocked — including a node dormant for 2,511 days (~6.9 years, NA941004-SAL) and another dormant 1,400 days (~3.8 years, tsm03, literally named DONOTDELETE_GVX0WEPPD02S).
Minimum Password Alphabetic/Uppercase/Lowercase/Numeric/Special-Character requirements are all set to 0 on every one of the 6 servers — only password length and expiration period vary server-to-server.
Only tsm03 has an SSL failover port configured (1542) for server-to-server replication; the other 5 servers show a blank SSL port on every replication peer definition, meaning database/data replication traffic rides plaintext TCP port 1500. Inter-server administrative peer-password hygiene is also inconsistent: lab10 and NA941005-SAL have 0 of their peer definitions password-protected, while tsm03 has all 9 of its peers password-protected (but zero of them use SSL).
Ten findings surfaced only by cross-referencing raw vendor export data — IBM Spectrum Protect CLI output, VMware vCenter exports, and HP Primera array output — from Y:\Temp Download\RBS\July 14, ranked by severity. None of these are visible from aggregate VOI telemetry alone; each required reading the underlying raw fields.
Sixteen of 25 fabric switches reported firmware in this collection — 12 Brocade and 4 Cisco MDS — and 12 of those 16 carry a confirmed applicable CVE.
| Vendor | Product | Fabric OS / NX-OS Version | Switches |
|---|---|---|---|
| Brocade | Fabric OS | v9.2.1a | 2 |
| Brocade | Fabric OS | v9.2.1b | 2 |
| Brocade | Fabric OS | v8.2.3e2 | 2 |
| Brocade | Fabric OS | v8.2.2d | 6 |
| Cisco MDS 9000 | NX-OS | 8.3(2) | 4 |
| Fleet Total (firmware-confirmed) | 16 | ||
Observed: FOS v8.2.2d • 6 switches — inside affected range (v8.2.3e2 already past fix) • Affected range: Before 8.2.3e1
Observed: FOS v9.2.1a (2) + v9.2.1b (2) • 4 switches — below fix • Affected range: Before 9.2.1c2; 9.2.2 – 9.2.2a
Observed: FOS v9.2.1a (2) + v9.2.1b (2) • 4 switches — below fix • Affected range: Before 9.2.1c2; 9.2.2 – 9.2.2a; 10.0.0
Observed: FOS v9.2.1a • 2 switches — inside affected range (v9.2.1b already past fix) • Affected range: Before 9.2.0c; 9.2.1 – 9.2.1a
Observed: FOS v9.2.1a (2) + v8.2.2d (6) • 8 switches — inside affected range • Affected range: Before 8.2.3e2; 9.0.0 – 9.2.0c; 9.2.1 – 9.2.1a
Six switches run Fabric OS v8.2.2d — the single oldest firmware train in the estate. CVE-2024-5461 and CVE-2024-10403 are open on every v8.2.2d switch and already closed on the v8.2.3e2 pair in the same fabric — an active, CVE-confirmed patch gap on 75% of the estate’s 8.2.x population.
Ranked by impact (CVSS/severity × KEV or active-exploitation status × effort). The KEV-driven and backup-authentication items lead the plan — VMware build verification, the tsm03 EOL/auth rebuild, and the fleet-wide node-lockout cleanup deliver the largest risk reduction relative to effort.
| # | Action | Group | Priority | Driving CVEs |
|---|---|---|---|---|
| 1 | Confirm exact ESXi/vCenter build string on all 556 hosts + 6 vCenters | Virtual | CRIT | CVE-2025-22224/22225/2024-37079 (KEV) |
| 2 | Upgrade tsm03 off EOL Spectrum Protect v7.1.3.0; enable lockout/min password length | Backup | CRIT | Hidden Gem #1 |
| 3 | Bulk-lock dormant (>180d) backup-client nodes fleet-wide (981 unlocked) | Backup | CRIT | Hidden Gem #2 |
| 4 | Patch IBM Storwize V7000 (5) + SVC (1) past 7.8.1.15 / 8.2.1.17 | Storage | CRIT | CVE-2022-0778, CVE-2021-38969, CVE-2022-43873 |
| 5 | Upgrade HPE 3PAR OS 3.3.2.159 fleet (4 devices) above 4.3.3 | Storage | CRIT | CVE-2021-26588 |
| 6 | Plan Dell EMC Data Domain major-version upgrade off DD OS 7.1.x (2 devices) | Storage | CRIT | CVE-2022-31813, CVE-2022-36760 — no in-branch fix exists |
| 7 | Confirm XtremIO XMS build; upgrade past 6.4.0-22 (1 device) | Storage | CRIT | CVE-2022-31228, CVE-2019-18578 |
| 8 | Upgrade Cisco ISE nodes off vmx-08/RHEL6 — network access control infrastructure | Virtual | HIGH | Hidden Gem #3 |
| 9 | Remediate 361 VMs with guestToolsNotInstalled; prioritize powered-on hosts | Virtual | HIGH | Hidden Gem #4 |
| 10 | Plan migration/decommission for 567 VMs on EOL guest OS (2003/2008/2000/RHEL6) | Virtual | HIGH | Hidden Gem #5 |
| 11 | Enforce password complexity requirements on all 6 Spectrum Protect servers | Backup | HIGH | Hidden Gem #6 |
| 12 | Patch Brocade v8.2.2d switches (6) to 8.2.3e1+ | SAN Switch | HIGH | CVE-2024-5461, CVE-2024-10403 |
| 13 | Patch Brocade v9.2.1a/b switches (4) to 9.2.1c2+ | SAN Switch | HIGH | CVE-2025-58382, CVE-2026-0383, CVE-2024-7517 |
| 14 | Enable SSL for inter-server Spectrum Protect replication (5 of 6 servers plaintext) | Backup | MED | Hidden Gem #7 |
| 15 | Configure a real remote syslog destination on all 5 HP Primera arrays | Storage | MED | Hidden Gem #8 |
| 16 | Run Cisco Software Checker against NX-OS 8.3(2) (4 switches) | SAN Switch | MED | Coverage gap — no confirmed CVE yet |
| 17 | Verify HPE 3PAR OS 3.2.2.709 support status; plan refresh (1 device) | Storage | MED | EOL, unresearched — no confirmed CVE |
| 18 | Standardize NetApp ONTAP fleet; retire 9.8P21 (past Limited Support) | Storage | MED | CVE-2026-22050/22052; EOL compliance |
| 19 | Confirm HMC appliance release (lshmc -V); plan Power6/7 refresh | Virtual | HIGH | EOL — no vendor patch path |
| 20 | Audit and tighten TSM VM-backup proxy-node scoping | Backup | MED | Hidden Gem #10 |
Same checks, your estate
Every remediation item above started as a line in a configuration file nobody had read.
Infrastructure Security Assessment, starts at $2,500. No agents, vendor agnostic.
Every finding in this report traces to a live query or a named raw-data file on the date below. Nothing here is inferred without disclosure, and no CVE ID was invented.
Visual One Intelligence (VisualOne), client ACME Widget, collection date July 14, 2026 (internally tracked as period_id 4213, with several bulk procs returning a mixed 4213/4214 rolling window through July 15, 2026). Correction from initial request: period_id 1413 — the value initially supplied for this engagement — resolves to a Fabric-OS-context-only period dated January 17, 2026, not July 14, and returns empty result sets for the Storage, Device, and Virtual contexts entirely. Period_id 4213 was identified as the correct cross-context period for July 14, 2026 and used throughout this report.
Procs queried: enterprise_devices_proc, enterprise_storage_all_devices_proc, enterprise_switch_proc, enterprise_virtual_summary_proc, visualone_list_units (devices/switches/esx_hosts). enterprise_virtual_all_vms_proc was attempted for VM-level detail but timed out at this estate’s scale (single vCenters reporting 1,000+ VMs) — Section 04 (Virtual Machine Security) is sourced from raw per-vCenter export files instead (see below).
Directory: Y:\Temp Download\RBS\July 14. VMware: 6 VMWARE_DEVICE_COMPARISON_output.jsn exports (2MB–731MB; the two largest were processed via streaming grep extraction only, never loaded in full, to avoid memory/context limits), covering 4,914 VM records across 6 vCenters. Backup: 6 TSM_BACKUP-* folders, each containing ~30 IBM Spectrum Protect CLI output files (query system, query node, query replserver, query proxynode, and related commands). Storage: 5 HP_PRIMERA_DEVICE-* raw JSON exports (2MB–47MB) cross-referenced for encryption and remote-logging configuration.
Tier 1: CISA KEV catalog, NVD, CVE.org. EUVD, OSV.dev, and VulnCheck NVD++ were considered but did not surface additional confirmed findings beyond NVD/CVE.org for this inventory.
Vendor PSIRT: Dell Security Advisories (DSA), HPE Security Bulletin Library, NetApp Security Advisories (NTAP-), IBM Security Advisories, Broadcom/Brocade Security Advisories, Cisco PSIRT openVuln.
Vendor corpus: remote qdrant-storage MCP (SSE transport) — queried for every vendor; returned indexed content for VMware vSphere and NetApp ONTAP product documentation only; did not contain PSIRT-indexed CVE text for Dell Data Domain/XtremIO, Brocade, or Cisco.
num_snapshots/snapshot_size) were not reliably populated in the raw VMware export — presence of a snapshot could be confirmed, but not its age or size, across all 6 vCenters.CISA KEV catalog as queried live on July 15, 2026. No formal catalog-version/build number is published by CISA; queries were run against the live catalog search interface on the stated date.
A subsequent independent verification pass re-checked every CVE in this report against NVD, CVE.org, CISA KEV, and vendor advisory pages, and corrected five errors found in the original draft: (1) CVE-2022-0778 was incorrectly marked KEV-listed — it is not on the CISA KEV catalog, and the “2022-03-15” date was OpenSSL’s patch-release date, not a KEV addition date; the KEV-listed CVE count was corrected from 4 to 3 and headline Critical/High counts adjusted accordingly. (2) CVE-2022-31813 was attributed to the wrong Dell advisory (DSA-2022-302, which does not reference this CVE) with fabricated fix versions; corrected to DSA-2023-389 with fix versions 7.12.0.0+/7.7.5.20+/7.10.1.10+. (3) CVE-2021-26588’s affected-range conflated HPE 3PAR OS and HPE Primera OS version numbering; corrected to the 3PAR-specific range and fix floor. (4) CVE-2025-22225’s device line showed a CVSS score (9.3) that actually belongs to sibling CVE-2025-22224; corrected to 8.2, moving this finding from the Critical to the High bucket. (5) CVE-2026-23594 was described as RESERVED with no live record; it in fact has a published HPE bulletin (HPESBST04995 rev.1, CVSS 8.8) — the report’s conclusion that observed firmware already meets the fixed baseline was correct, but the CVE’s status description was not. Separately, for CVE-2021-38969 and CVE-2022-43873, note that IBM’s own CNA-assigned CVSS scores (5.6 and 6.3 respectively) are substantially lower than the NVD scores cited in this report (9.8 and 8.8); this report cites NVD consistently across all findings, but the vendor/NVD split is disclosed here for completeness. All other CVE IDs, CVSS scores, KEV statuses, and vendor advisory citations in this report were independently confirmed accurate.