Home / Security / Advisories / NTAP-20200626-0001

NTAP-20200626-0001 — CVE-2020-8573 Default Account Vulnerability in the NetApp HCI Baseboard Management Controller (BMC) - H610C, H615C and H610S

Published 2020-06-26 · Updated 2020-10-01 · Status: Final · Exploitation: Public · Severity: MEDIUM 6.5 · ONTAP affected: No — other NetApp product

Official advisory: NTAP-20200626-0001 on security.netapp.com ↗. Affected versions, fixed releases, and workarounds live there — this page is a summary.

Product family: SolidFire / NetApp HCI  |  other NetApp product  |  highest CVSS: 6.5

CVEs in this advisory

What the CVE records say

CVE-2020-8573 — The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During upgrades to Element 11.8 and 12.0 or the Compute Firmware Bundle 12.2.92 the BMC account password on the H610C, H615C and H610S platforms is reset to the default documented value which could allow remote attackers to cause a Denial of Service (DoS).

Impact

Successful exploitation of this vulnerability could lead to Denial of Service (DoS). <br><br> <b>This affects the BMCs of the NetApp HCI H610C, H615C and H610S platforms.</b> <br><br> The vulnerability is addressed by following the "Changing the default IPMI password for H610C, H615C, and H610S nodes" documentation used during the initial setup - an Element update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to Element. <br><br> Element and the Compute Firmware Bundle will be patched to prevent the BMC password reset during future upgrades. <br><br> Continue to monitor the advisory for updates.

Affected products

Official fixes

What to do

  1. Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
  2. Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
  3. Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
  4. Track follow-ups in the site CVE index and the security RSS feed.

Related reading

Browse all ONTAP CVEs → · Security hub