Answer in brief
CVE-2023-41993 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps netapp/cloud_insights_acquisition_unit (generic), netapp/cloud_insights_storage_workload_security_agent (generic), debian/debian_linux (generic), fedoraproject/fedora (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps netapp/cloud_insights_acquisition_unit (generic), netapp/cloud_insights_storage_workload_security_agent (generic), debian/debian_linux (generic), fedoraproject/fedora (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| netapp/cloud_insights_acquisition_unitgeneric | 0 | Not reported |
| netapp/cloud_insights_storage_workload_security_agentgeneric | 0 | Not reported |
| debian/debian_linuxgeneric | 11.0 || 12.0 | Not reported |
| fedoraproject/fedorageneric | 39 | Not reported |
| fedoraproject/fedorageneric | 37 | Not reported |
| fedoraproject/fedorageneric | 38 | Not reported |
| oracle/graalvmgeneric | 20.3.13 | Not reported |
| oracle/graalvmgeneric | 21.3.9 | Not reported |
| apple/ipad_osgeneric | >=0 <17.0.1 | 17.0.1 |
| apple/iphone_osgeneric | >=0 <17.0.1 | 17.0.1 |
| oracle/jdkgeneric | 1.8.0 | Not reported |
| oracle/jregeneric | 1.8.0 | Not reported |
| apple/macosgeneric | >=0 <14.0 | 14.0 |
| Apple/macOSgeneric | >=unspecified <14 | 14 |
| netapp/oncommand_insightgeneric | 0 | Not reported |
| netapp/oncommand_workflow_automationgeneric | 0 | Not reported |
Published upstream
Sep 21, 2023
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Nov 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 25, 2023
Evidence: source:kev:kev:kev:recordThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2023-41993 records a High severity vulnerability in CISA ADP Vulnrichment. The current sources mark it as known exploited. The current feed maps netapp/cloud_insights_acquisition_unit (generic), netapp/cloud_insights_storage_workload_security_agent (generic), debian/debian_linux (generic), fedoraproject/fedora (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps netapp/cloud_insights_acquisition_unit (generic), netapp/cloud_insights_storage_workload_security_agent (generic), debian/debian_linux (generic), fedoraproject/fedora (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| netapp/cloud_insights_acquisition_unitgeneric | 0 | Not reported |
| netapp/cloud_insights_storage_workload_security_agentgeneric | 0 | Not reported |
| debian/debian_linuxgeneric | 11.0 || 12.0 | Not reported |
| fedoraproject/fedorageneric | 39 | Not reported |
| fedoraproject/fedorageneric | 37 | Not reported |
| fedoraproject/fedorageneric | 38 | Not reported |
| oracle/graalvmgeneric | 20.3.13 | Not reported |
| oracle/graalvmgeneric | 21.3.9 | Not reported |
| apple/ipad_osgeneric | >=0 <17.0.1 | 17.0.1 |
| apple/iphone_osgeneric | >=0 <17.0.1 | 17.0.1 |
| oracle/jdkgeneric | 1.8.0 | Not reported |
| oracle/jregeneric | 1.8.0 | Not reported |
| apple/macosgeneric | >=0 <14.0 | 14.0 |
| Apple/macOSgeneric | >=unspecified <14 | 14 |
| netapp/oncommand_insightgeneric | 0 | Not reported |
| netapp/oncommand_workflow_automationgeneric | 0 | Not reported |
Published upstream
Sep 21, 2023
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Nov 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Sep 25, 2023
Evidence: source:kev:kev:kev:recordThe issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
Quoted source text, attributed separately from HOL analysis.