Home / Security / Advisories / NTAP-20200226-0001

NTAP-20200226-0001 — CVE-2019-17274 Default Privileged Account Vulnerability in the NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller

Published 2020-02-26 · Updated 2020-02-26 · Status: Final · Exploitation: Not public

Official advisory: NTAP-20200226-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

CVEs in this advisory

Affected products

What to do

  1. Check your ONTAP versions against the official advisory's affected-versions table.
  2. If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
  3. If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).

Related reading

Browse all ONTAP CVEs → · Security hub