Vulnerability Description
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netapp | Fabric-Attached Storage 8700 Firmware | <= 13.1 |
| Netapp | Fabric-Attached Storage 8700 | - |
| Netapp | Fabric-Attached Storage 8300 Firmware | <= 13.1 |
| Netapp | Fabric-Attached Storage 8300 | - |
| Netapp | All Flash Fabric-Attached Storage A400 Firmware | <= 13.1 |
| Netapp | All Flash Fabric-Attached Storage A400 | - |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20200226-0001/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20200226-0001/Vendor Advisory
FAQ
What is CVE-2019-17274?
CVE-2019-17274 is a vulnerability with a CVSS score of 7.8 (HIGH). NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary comma...
How severe is CVE-2019-17274?
CVE-2019-17274 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-17274?
Check the references section above for vendor advisories and patch information. Affected products include: Netapp Fabric-Attached Storage 8700 Firmware, Netapp Fabric-Attached Storage 8700, Netapp Fabric-Attached Storage 8300 Firmware, Netapp Fabric-Attached Storage 8300, Netapp All Flash Fabric-Attached Storage A400 Firmware.