9.8
CVSSv3

CVE-2019-5490

Published: 21/03/2019 Updated: 24/08/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netapp service_processor 5.5

netapp service_processor 4.5

netapp service_processor 3.7

netapp service_processor 2.8

netapp service_processor 5.2

netapp service_processor 4.2

netapp service_processor 2.5

netapp service_processor 3.4

netapp service_processor 4.1

netapp service_processor 3.3

netapp service_processor 5.1

netapp service_processor 2.4.1

netapp service_processor 3.2

netapp service_processor 2.4

netapp service_processor 3.1.2

netapp service_processor 2.3.2

netapp service_processor 3.0.4

netapp service_processor 2.2.5