CVE-2019-17274

NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:netapp:fabric-attached_storage_8700_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:fabric-attached_storage_8700:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:netapp:fabric-attached_storage_8300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:fabric-attached_storage_8300:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:netapp:all_flash_fabric-attached_storage_a400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:netapp:all_flash_fabric-attached_storage_a400:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:32

Type Values Removed Values Added
References () https://security.netapp.com/advisory/ntap-20200226-0001/ - Vendor Advisory () https://security.netapp.com/advisory/ntap-20200226-0001/ - Vendor Advisory

Information

Published : 2020-02-26 18:15

Updated : 2024-11-21 04:32


NVD link : CVE-2019-17274

Mitre link : CVE-2019-17274

CVE.ORG link : CVE-2019-17274


JSON object : View

Products Affected

netapp

  • fabric-attached_storage_8700_firmware
  • fabric-attached_storage_8700
  • all_flash_fabric-attached_storage_a400_firmware
  • all_flash_fabric-attached_storage_a400
  • fabric-attached_storage_8300
  • fabric-attached_storage_8300_firmware
CWE
CWE-1188

Insecure Default Initialization of Resource