First published: Wed Feb 26 2020(Updated: )
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Credit: security-alert@netapp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Netapp Fabric-attached Storage 8700 Firmware | <=13.1 | |
Netapp Fabric-attached Storage 8700 | ||
Netapp Fabric-attached Storage 8300 Firmware | <=13.1 | |
Netapp Fabric-attached Storage 8300 | ||
Netapp All Flash Fabric-attached Storage A400 Firmware | <=13.1 | |
Netapp All Flash Fabric-attached Storage A400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-17274.
The severity of CVE-2019-17274 is high with a severity value of 7.8.
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 are affected by CVE-2019-17274.
Unauthorized arbitrary command execution can occur via local access to the affected NetApp devices.
Yes, the fix for CVE-2019-17274 is to update the BMC firmware to version 13.1P1 or later.