Home / Security / Advisories / NTAP-20200626-0001
NTAP-20200626-0001 — CVE-2020-8573 Default Account Vulnerability in the NetApp HCI Baseboard Management Controller (BMC) - H610C, H615C and H610S
Published 2020-06-26 · Updated 2020-10-01 · Status: Final · Exploitation: Public · Severity: MEDIUM 6.5 · ONTAP affected: No — other NetApp product
Product family: SolidFire / NetApp HCI | other NetApp product | highest CVSS: 6.5
CVEs in this advisory
- CVE-2020-8573 — MEDIUM · CVSS 6.5 · site index
What the CVE records say
CVE-2020-8573 — The NetApp HCI H610C, H615C and H610S Baseboard Management Controllers (BMC) are shipped with a documented default account and password that should be changed during the initial node setup. During upgrades to Element 11.8 and 12.0 or the Compute Firmware Bundle 12.2.92 the BMC account password on the H610C, H615C and H610S platforms is reset to the default documented value which could allow remote attackers to cause a Denial of Service (DoS).
Impact
Successful exploitation of this vulnerability could lead to Denial of Service (DoS). <br><br> <b>This affects the BMCs of the NetApp HCI H610C, H615C and H610S platforms.</b> <br><br> The vulnerability is addressed by following the "Changing the default IPMI password for H610C, H615C, and H610S nodes" documentation used during the initial setup - an Element update is not required. <br><br> While the BMC firmware update requires a reboot of the BMC, the process is nondisruptive to Element. <br><br> Element and the Compute Firmware Bundle will be patched to prevent the BMC password reset during future upgrades. <br><br> Continue to monitor the advisory for updates.
Affected products
- NetApp HCI Baseboard Management Controller (BMC) - H610C
- NetApp HCI Baseboard Management Controller (BMC) - H610S
- NetApp HCI Baseboard Management Controller (BMC) - H615C
Official fixes
- NetApp HCI Baseboard Management Controller (BMC) - H610C — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H610C — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H615C — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H615C — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H610S — vendor fix ↗
- NetApp HCI Baseboard Management Controller (BMC) - H610S — vendor fix ↗
What to do
- Compare your installed product and version against the affected list above and the official advisory's affected-versions table.
- Apply the fixed release named in the official advisory, or the documented workaround if no fix ships yet.
- Limit management-plane exposure (BMC/management interfaces, web UIs, SNMP) until patched.
- Track follow-ups in the site CVE index and the security RSS feed.
Related reading
- Site CVE index — every CVE we track, split by year
- Security hub — recent NetApp advisories and what changed
- Security hardening baseline — applies to NetApp management planes generally
- Every NetApp advisory published in 2020