CVE-2019-17274: Netapp All Flash Fabric-Attached Storage a400 Firmware
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
NetApp FAS 8300/8700 and AFF A400 Baseboard Management Controller (BMC) firmware versions 13.x prior to 13.1P1 were shipped with a default account enabled that could allow unauthorized arbitrary command execution via local access.
Affected products
- Netapp All Flash Fabric-Attached Storage a400 Firmware: up to and including 13.1
- Netapp Fabric-Attached Storage 8300 Firmware: up to and including 13.1
- Netapp Fabric-Attached Storage 8700 Firmware: up to and including 13.1
Published 2020-02-26. Last modified 2026-06-17.