High severity7.8NVD Advisory· Published Feb 26, 2020· Updated Jun 17, 2026
CVE-2019-17274
CVE-2019-17274
Description
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Affected products
5- Range: <13.1P1
- NetApp/NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controllerv5Range: 13.x prior to 13.1P1
- cpe:2.3:o:netapp:fabric-attached_storage_8700_firmware:*:*:*:*:*:*:*:*Range: <=13.1
- cpe:2.3:o:netapp:fabric-attached_storage_8300_firmware:*:*:*:*:*:*:*:*Range: <=13.1
- cpe:2.3:o:netapp:all_flash_fabric-attached_storage_a400_firmware:*:*:*:*:*:*:*:*Range: <=13.1
Patches
Vulnerability mechanics
References
1- security.netapp.com/advisory/ntap-20200226-0001/nvdVendor Advisory
News mentions
0No linked articles in our index yet.