Home / Security / Advisories / NTAP-20190305-0001
NTAP-20190305-0001 — CVE-2019-5490 Default Privileged Account Vulnerability in the NetApp Service Processor
Published 2019-03-05 · Updated 2019-04-11 · Status: Final · Exploitation: Not public · Severity: CRITICAL 9.8 · ONTAP affected: Yes
Product family: ONTAP · Other NetApp products | ONTAP-relevant | highest CVSS: 9.8
CVEs in this advisory
- CVE-2019-5490 — CRITICAL · CVSS 9.8 · site index
What the CVE records say
CVE-2019-5490 — Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.
Impact
Exploitation of this vulnerability can result in unauthorized arbitrary command execution. <html> <body> <p>First Fixed in Releases: </p> <table align="left" border="1" cellpadding="0" cellspacing="0"> <tbody> <tr> <td width="110"> <p><strong>SP Firmware</strong></p> </td> <td> <p><strong>Storage Systems</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.5</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.4</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.3</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.2</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.1</strong></p> </td> <td width="93"> <p><strong>ONTAP 9.0</strong></p> </td> <td width="93"> <p><strong>ONTAP 8.3</strong></p> </td> <td width="93"> <p><strong>ONTAP 8.2</strong></p> </td> </tr> <tr> <td width="110"> <p>SP 5.x</p> </td> <td> <p>AFF A300, AFF A200, FAS8200, FAS2650, FAS2620</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.5P1</p> </td> <td width="93"> <p>5.2P2</p> </td> <td width="93"> <p>5.1P4</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td width="110"> <p>SP 4.x</p> </td> <td> <p>AFF A700, FAS9000</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.5P1</p> </td> <td width="93"> <p>4.2P3</p> </td> <td width="93"> <p>4.1P7</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td rowspan="2" width="110"> <p>SP 3.x</p> </td> <td> <p>AFF8080, AFF8060, AFF8040, AFF8020</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.4P3</p> </td> <td width="93"> <p>3.3P5</p> </td> <td width="93"> <p>3.2P1</p> </td> <td width="93"> <p>3.1.2P3</p> </td> <td width="93"> <p>N/A</p> </td> </tr> <tr> <td> <p>FAS8080, FAS8060, FAS8040, FAS8020</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.7P1</p> </td> <td width="93"> <p>3.4P3</p> </td> <td width="93"> <p>3.3P5</p> </td> <td width="93"> <p>3.2P1</p> </td> <td width="93"> <p>3.1.2P3</p> </td> <td width="93"> <p>3.0.4P1*</p> </td> </tr> <tr> <td rowspan="2" width="110"> <p>SP 2.x</p> </td> <td> <p>FAS2554, FAS2552, FAS2520 (ONTAP 8.2.2 and later)</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.8P1</p> </td> <td width="93"> <p>2.5P1</p> </td> <td width="93"> <p>2.4.1P2</p> </td> <td width="93"> <p>2.4P1</p> </td> <td width="93"> <p>2.3.2P4</p> </td> <td width="93"> <p>2.2.5P1</p> </td> </tr> <tr> <td> <p>FAS2240-4, FAS2240-2, FAS2220 (ONTAP 9.1 is the last supported release)</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>N/A</p> </td> <td width="93"> <p>2.4.1P2</p> </td> <td width="93"> <p>2.4P1</p> </td> <td width="93"> <p>2.3.2P4</p> </td> <td width="93"> <p>2.2.5P1</p> </td> </tr> </tbody> </table> <p> </p> <p>N/A = "Not Applicable" (i.e. no fix required)</p><br> <p><a href="https://kb.netapp.com/app/answers/answer_view/a_id/1087275">MD5 checksums for Service Processor Security Patch Files</a></p><br> <p><strong>Unaffected platforms/firmware versions:</strong><br> The FAS/AFF Baseboard Management Controller (BMC) , Service Processor 1.x firmware versions, ONTAP Select and Cloud Volumes ONTAP are not affected by this vulnerability – this includes the following platforms: AFF A220, FAS2720, FAS2750, AFF A800, AFF A700s, FAS6290, FAS6280, FAS6250, FAS6240, FAS6220, FAS6210, FAS3270, FAS3250, FAS3240, FAS3220, FAS3210 and V-Series variants </p> <p>*Although NetApp has found no evidence of exposure in the 3.0.x Service Processor firmware, a patch has been made available out of an abundance of caution.</p> <p>Once patched Service Processor firmware has been applied to a controller there is no need to update ONTAP. </p> <p>While the Service Processor firmware update requires a reboot of the Service Processor, the process is non-disruptive to ONTAP. </p> <p>Certain versions of clustered Data ONTAP and Data ONTAP operating in 7-Mode included affected versions of the Service Processor firmware. P-releases that include the patched Service Processor firmware are available for ONTAP 9.x versions under Full Support. There are no plans to create a Data ONTAP operating in 7-Mode 8.2.5 P-release that includes the patched Service Processor firmware - use the appropriate Service Processor patch from the System Firmware + Diagnostics Download page for this version. </p> </body> </html>
Affected products
- Clustered Data ONTAP
- Data ONTAP operating in 7-Mode
- Service Processor
Official fixes
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Service Processor — vendor fix ↗
References
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2019