← Vulnerability feed

Vulnerability record · CVE-2019-5490 · published 21 March 2019

CVE-2019-5490: Netapp service processor insecure default initialization vulnerability

NNetapp · Service Processor

Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.

9.8 CVSS 3.0 Critical EPSS 3.5% · top 11.3% CWE-1188 · Insecure default initialization
9.8CVSS 3.0 base score, v2 10.0
3.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service Processor firmware IMMEDIATELY.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-5490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-2215Android Binder use-after-free allows kernel privilege escalationCVE-2019-2215 is a use-after-free in binder.c in the Android/Linux kernel that lets a local application escalate privileges to the kernel. It matters…KEVEPSS 72%analysed7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed7.8CVE-2019-14814Linux kernel heap-based buffer overflow vulnerabilityThere is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows …EPSS 0.87%7.8CVE-2019-14816Linux kernel heap-based buffer overflow vulnerabilityThere is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local …EPSS 0.91%7.8CVE-2019-14835Linux kernel classic buffer overflow vulnerabilityA buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers t…EPSS 0.62%7.5CVE-2019-16995Linux kernel memory leak vulnerabilityIn the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may ca…EPSS 3.5%7.5CVE-2016-10708Openbsd openssh null pointer dereference vulnerabilitysshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NE…EPSS 16%7.5CVE-2016-8610Openssl uncontrolled resource consumption vulnerabilityA denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALE…EPSS 40%

Source: NIST National Vulnerability Database (record CVE-2019-5490), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.