CVE-2019-17274: High severity netapp all flash fabric-attached storage 8700 firmware vulnerability
Published Feb 26, 2020
·Updated
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Affected Software
6 affected components
NetApp Fabric-attached Storage 8700 Firmware<=13.1
NetApp Fabric-attached Storage 8700
NetApp Fabric-attached Storage 8300 Firmware<=13.1
NetApp Fabric-attached Storage 8300
NetApp All Flash Fabric-attached Storage A400 Firmware<=13.1
NetApp All Flash Fabric-attached Storage A400
Event History
Feb 26, 2020
CVE Published
via MITRE·05:38 PM
Data Sourced
via MITRE·05:38 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-17274.
2
What is the severity of CVE-2019-17274?
The severity of CVE-2019-17274 is high with a severity value of 7.8.
3
What is affected by CVE-2019-17274?
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 are affected by CVE-2019-17274.
4
How can unauthorized arbitrary command execution occur?
Unauthorized arbitrary command execution can occur via local access to the affected NetApp devices.
5
Is there a fix for CVE-2019-17274?
Yes, the fix for CVE-2019-17274 is to update the BMC firmware to version 13.1P1 or later.