Home / Security / Advisories / NTAP-20200226-0001

NTAP-20200226-0001 — CVE-2019-17274 Default Privileged Account Vulnerability in the NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller

Published 2020-02-26 · Updated 2020-02-26 · Status: Final · Exploitation: Not public · Severity: HIGH 7.8 · ONTAP affected: Yes

Official advisory: NTAP-20200226-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: ONTAP · Baseboard management controllers  |  ONTAP-relevant  |  highest CVSS: 7.8

CVEs in this advisory

What the CVE records say

CVE-2019-17274 — NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.

Impact

Exploitation of this vulnerability can result in unauthorized arbitrary command execution via local access. <br><br> This only affects the BMC of FAS 8300/8700 and AFF A400 storage systems. The Service Processors (SP) or BMCs used on other storage system models are not affected by this specific vulnerability. <br><br> The vulnerability is addressed by applying patched firmware to the BMC of the FAS 8300/8700 and AFF A400 systems. An ONTAP update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to ONTAP. <br><br> ONTAP 9.7 includes the patched BMC firmware.

Affected products

Official fixes

What to do

  1. Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
  4. Harden in parallel: security hardening baseline and ransomware protection on ONTAP.

Related reading

Browse all ONTAP CVEs → · Security hub