CVE-2019-17274

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2020
Last modified:
24/08/2020

Description

NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:netapp:fabric-attached_storage_8700_firmware:*:*:*:*:*:*:*:* 13.1 (including)
cpe:2.3:h:netapp:fabric-attached_storage_8700:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:fabric-attached_storage_8300_firmware:*:*:*:*:*:*:*:* 13.1 (including)
cpe:2.3:h:netapp:fabric-attached_storage_8300:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:all_flash_fabric-attached_storage_a400_firmware:*:*:*:*:*:*:*:* 13.1 (including)
cpe:2.3:h:netapp:all_flash_fabric-attached_storage_a400:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools