Home / Security / Advisories / NTAP-20190802-0003

NTAP-20190802-0003 — CVE-2019-5500 Denial of Service (DoS) Vulnerability in the NetApp Service Processor and Baseboard Management Controller

Published 2019-08-02 · Updated 2019-11-05 · Status: Final · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: No — other NetApp product

Official advisory: NTAP-20190802-0003 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: Baseboard management controllers · Other NetApp products  |  other NetApp product  |  highest CVSS: 7.5

CVEs in this advisory

What the CVE records say

CVE-2019-5500 — Certain versions of the NetApp Service Processor and Baseboard Management Controller firmware allow a remote unauthenticated attacker to cause a Denial of Service (DoS).

Impact

Exploitation of this vulnerability can allow an attacker to cause a Denial of Service (DoS) on Storage Systems containing affected Service Processor or Baseboard Management Controller firmware. <br><br> Affected Platforms: FAS26x0, FAS27x0, FAS8200 or AFF C190, AFF A200, AFF A220, AFF A300 <br><br> The vulnerability is addressed by applying patched Service Processor or BMC firmware. An ONTAP update is not required. <br><br> While the Service Processor and BMC firmware updates require a reboot of the Service Processor or BMC, the process is non-disruptive to ONTAP.

Affected products

Official fixes

References

What to do

  1. Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
  2. Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
  3. Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
  4. Track follow-ups in the site CVE index and the security RSS feed.

Related reading

Browse all ONTAP CVEs → · Security hub