CVE-2019-5490
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.
Affected (42)
Products: Netapp: Service Processor
Configuration A
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.5 |
Configuration B
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.4 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.8 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.3 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.5 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.2 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4.1 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.1 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.4 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 9.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.3.2 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 8.3 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.2.5 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | Version 8.2 |
References (4)
Source: security-alert@netapp.com
Source: security-alert@netapp.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.