Home / Security / Advisories / NTAP-20190627-0001
NTAP-20190627-0001 — CVE-2019-5497 Default Privileged Account Vulnerability in the NetApp AFF A700s Baseboard Management Controller
Published 2019-06-27 · Updated 2019-08-14 · Status: Final · Exploitation: Not public · Severity: CRITICAL 9.8 · ONTAP affected: Yes
Product family: Baseboard management controllers · ONTAP | ONTAP-relevant | highest CVSS: 9.8
CVEs in this advisory
- CVE-2019-5497 — CRITICAL · CVSS 9.8 · site index
What the CVE records say
CVE-2019-5497 — NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution.
Impact
Exploitation of this vulnerability can result in unauthorized arbitrary command execution. <br><br> <b>This only affects the BMC of an AFF A700s storage system. The Service Processors (SP) or BMCs used on other storage system models are not affected by this specific vulnerability.</b> <br><br> The vulnerability is addressed by applying patched BMC firmware to the BMC of the AFF A700s system. An ONTAP update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to ONTAP. <br><br> Certain versions of clustered Data ONTAP included affected versions of the AFF A700s BMC firmware. ONTAP P-releases that include the patched AFF A700s BMC firmware will be available for all versions under Full Support except 9.1 which needs to be updated using the BMC patch. Continue to monitor the advisory for updates.
Affected products
- AFF Baseboard Management Controller (BMC) - A700s
- Clustered Data ONTAP
Official fixes
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
- AFF Baseboard Management Controller (BMC) - A700s — vendor fix ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2019