Home / Security / Advisories / NTAP-20190627-0001

NTAP-20190627-0001 — CVE-2019-5497 Default Privileged Account Vulnerability in the NetApp AFF A700s Baseboard Management Controller

Published 2019-06-27 · Updated 2019-08-14 · Status: Final · Exploitation: Not public · Severity: CRITICAL 9.8 · ONTAP affected: Yes

Official advisory: NTAP-20190627-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Baseboard management controllers · ONTAP  |  ONTAP-relevant  |  highest CVSS: 9.8

CVEs in this advisory

What the CVE records say

CVE-2019-5497 — NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.

Impact

Exploitation of this vulnerability can result in unauthorized arbitrary command execution. <br><br> <b>This only affects the BMC of an AFF A700s storage system. The Service Processors (SP) or BMCs used on other storage system models are not affected by this specific vulnerability.</b> <br><br> The vulnerability is addressed by applying patched BMC firmware to the BMC of the AFF A700s system. An ONTAP update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to ONTAP. <br><br> Certain versions of clustered Data ONTAP included affected versions of the AFF A700s BMC firmware. ONTAP P-releases that include the patched AFF A700s BMC firmware will be available for all versions under Full Support except 9.1 which needs to be updated using the BMC patch. Continue to monitor the advisory for updates.

Affected products

Official fixes

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub