A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
An attacker exploits a remote administrative service available on the FlashArray device to unauthorized create a new user account. The created account has elevated privileges (privileged access), which enables takeover of the matrix. The vulnerability is classified as improper privilege management (CWE-269), which indicates a lack of proper verification of privileges required to perform this operation.
An attacker can gain privileged access to the FlashArray matrix, which in practice means full control over stored data, device configuration, and potentially the entire storage infrastructure — leading to disclosure, modification, or destruction of data.
Apply patches available from the manufacturer according to references published at https://purestorage.com/security. Additionally, it is recommended to restrict access to remote administrative services only to trusted networks and to implement monitoring of new account creation on FlashArray devices.
Pure Storage FlashArray Purity//FA — versions indicated in the manufacturer's references (https://purestorage.com/security)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HPurestorage Purity\/\/fa
APPPurestorage6.5.06.0.7 – 6.0.96.1.8 – 6.1.255.3.17 – 5.3.216.3.0 – 6.3.146.4.0 – 6.4.106.2.0 – 6.2.17
Related vulnerabilities
FlashArray Purity — aktywne konto lokalne umożliwia privilege escalation
Command injection w Pure Storage Purity poprzez konfigurację SNMP
Zdalne wykonanie kodu z eskalacją uprawnień w Pure Storage FlashArray Purity
Obejście uwierzytelnienia w Pure Storage FlashArray Purity (CVSS 10.0)
Ujawnione dane uwierzytelniające w Pure Storage Purity//FA i Purity//FB