Home / Security / Advisories / NTAP-20200226-0001
NTAP-20200226-0001 — CVE-2019-17274 Default Privileged Account Vulnerability in the NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller
Published 2020-02-26 · Updated 2020-02-26 · Status: Final · Exploitation: Not public · Severity: HIGH 7.8 · ONTAP affected: Yes
Product family: ONTAP · Baseboard management controllers | ONTAP-relevant | highest CVSS: 7.8
CVEs in this advisory
- CVE-2019-17274 — HIGH · CVSS 7.8 · site index
What the CVE records say
CVE-2019-17274 — NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Impact
Exploitation of this vulnerability can result in unauthorized arbitrary command execution via local access. <br><br> This only affects the BMC of FAS 8300/8700 and AFF A400 storage systems. The Service Processors (SP) or BMCs used on other storage system models are not affected by this specific vulnerability. <br><br> The vulnerability is addressed by applying patched firmware to the BMC of the FAS 8300/8700 and AFF A400 systems. An ONTAP update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to ONTAP. <br><br> ONTAP 9.7 includes the patched BMC firmware.
Affected products
- Clustered Data ONTAP
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400
Official fixes
- FAS/AFF Baseboard Management Controller (BMC) - 8300/8700/A400 — vendor fix ↗
- Clustered Data ONTAP — vendor fix ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2020