Home / Security / Advisories / NTAP-20190305-0001

NTAP-20190305-0001 — CVE-2019-5490 Default Privileged Account Vulnerability in the NetApp Service Processor

Published 2019-03-05 · Updated 2019-04-11 · Status: Final · Exploitation: Not public · Severity: CRITICAL 9.8 · ONTAP affected: Yes

Official advisory: NTAP-20190305-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: ONTAP · Other NetApp products  |  ONTAP-relevant  |  highest CVSS: 9.8

CVEs in this advisory

What the CVE records say

CVE-2019-5490 — Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.

Impact

Exploitation of this vulnerability can result in unauthorized arbitrary command execution. <html> <body> <p>First Fixed in Releases:&nbsp;</p> <table align="left" border="1" cellpadding="0" cellspacing="0"> <tbody> <tr> <td width="110"> <p><strong>SP Firmware</strong></p> </td> <td> <p><strong>Storage Systems</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.5</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.4</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.3</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.2</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.1</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.0</strong></p> </td> <td width="93"> <p><strong>ONTAP 8.3</strong></p> </td> <td width="93"> <p><strong>ONTAP 8.2</strong></p> </td> </tr> <tr> <td width="110"> <p>SP 5.x</p> </td> <td> <p>AFF A300, AFF A200, FAS8200, FAS2650, FAS2620</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.2P2</p> </td> <td width="93"> <p>5.1P4</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td width="110"> <p>SP 4.x</p> </td> <td> <p>AFF A700, FAS9000</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.2P3</p> </td> <td width="93"> <p>4.1P7</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td rowspan="2" width="110"> <p>SP 3.x</p> </td> <td> <p>AFF8080, AFF8060, AFF8040, AFF8020</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.4P3</p> </td> <td width="93"> <p>3.3P5</p> </td> <td width="93"> <p>3.2P1</p> </td> <td width="93"> <p>3.1.2P3</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td> <p>FAS8080, FAS8060, FAS8040, FAS8020</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.4P3</p> </td> <td width="93"> <p>3.3P5</p> </td> <td width="93"> <p>3.2P1</p> </td> <td width="93"> <p>3.1.2P3</p> </td> <td width="93"> <p>3.0.4P1*</p> </td> </tr> <tr> <td rowspan="2" width="110"> <p>SP 2.x</p> </td> <td> <p>FAS2554, FAS2552, FAS2520&nbsp; (ONTAP 8.2.2 and later)</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.5P1</p> </td> <td width="93"> <p>2.4.1P2</p> </td> <td width="93"> <p>2.4P1</p> </td> <td width="93"> <p>2.3.2P4</p> </td> <td width="93"> <p>2.2.5P1</p> </td> </tr> <tr> <td> <p>FAS2240-4, FAS2240-2, FAS2220 (ONTAP 9.1 is the last supported release)</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>2.4.1P2</p> </td> <td width="93"> <p>2.4P1</p> </td> <td width="93"> <p>2.3.2P4</p> </td> <td width="93"> <p>2.2.5P1</p> </td> </tr> </tbody> </table> <p>&nbsp;</p> <p>N/A = "Not Applicable" (i.e. no fix required)</p><br> <p><a href="https://kb.netapp.com/app/answers/answer_view/a_id/1087275">MD5 checksums for Service Processor Security Patch Files</a></p><br> <p><strong>Unaffected platforms/firmware versions:</strong><br> The FAS/AFF Baseboard Management Controller (BMC) , Service Processor 1.x firmware versions, ONTAP Select and Cloud Volumes ONTAP are not affected by this vulnerability &ndash; this includes the following platforms: AFF A220, FAS2720, FAS2750, AFF A800, AFF A700s, FAS6290, FAS6280, FAS6250, FAS6240, FAS6220, FAS6210, FAS3270, FAS3250, FAS3240, FAS3220, FAS3210 and V-Series variants&nbsp;</p> <p>*Although NetApp has found no evidence of exposure in the 3.0.x Service Processor firmware, a patch has been made available out of an abundance of caution.</p> <p>Once patched Service Processor firmware has been applied to a controller there is no need to update ONTAP.&nbsp;&nbsp;</p> <p>While the Service Processor firmware update requires a reboot of the Service Processor, the process is non-disruptive to ONTAP.&nbsp;</p> <p>Certain versions of clustered Data ONTAP and Data ONTAP operating in 7-Mode included affected versions of the Service Processor firmware. P-releases that include the patched Service Processor firmware are available for ONTAP 9.x versions under Full Support. There are no plans to create a Data ONTAP operating in 7-Mode 8.2.5 P-release that includes the patched Service Processor firmware - use the appropriate Service Processor patch from the System Firmware + Diagnostics Download page for this version. </p> </body> </html>

Affected products

Official fixes

References

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub