CRITICAL🇵🇱 Wersja polska

CVE-2024-0003

CVSS 9.1v3.1pub. 2024-09-23upd. 2024-09-27

A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.

🤖 AI Analysis
How it works

An attacker exploits a remote administrative service available on the FlashArray device to unauthorized create a new user account. The created account has elevated privileges (privileged access), which enables takeover of the matrix. The vulnerability is classified as improper privilege management (CWE-269), which indicates a lack of proper verification of privileges required to perform this operation.

Impact

An attacker can gain privileged access to the FlashArray matrix, which in practice means full control over stored data, device configuration, and potentially the entire storage infrastructure — leading to disclosure, modification, or destruction of data.

Mitigation & patch

Apply patches available from the manufacturer according to references published at https://purestorage.com/security. Additionally, it is recommended to restrict access to remote administrative services only to trusted networks and to implement monitoring of new account creation on FlashArray devices.

Who is affected

Pure Storage FlashArray Purity//FA — versions indicated in the manufacturer's references (https://purestorage.com/security)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Purestorage Purity\/\/fa

    APP
    Purestorage
    6.5.06.0.7 – 6.0.96.1.8 – 6.1.255.3.17 – 5.3.216.3.0 – 6.3.146.4.0 – 6.4.106.2.0 – 6.2.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-0001CRITICAL10.0PL ✓same product

FlashArray Purity — aktywne konto lokalne umożliwia privilege escalation

CVE-2024-0005CRITICAL9.1PL ✓same product

Command injection w Pure Storage Purity poprzez konfigurację SNMP

CVE-2024-0004CRITICAL9.1PL ✓same product

Zdalne wykonanie kodu z eskalacją uprawnień w Pure Storage FlashArray Purity

CVE-2024-0002CRITICAL10.0PL ✓same product

Obejście uwierzytelnienia w Pure Storage FlashArray Purity (CVSS 10.0)

CVE-2022-32554CRITICAL9.8PL ✓same product

Ujawnione dane uwierzytelniające w Pure Storage Purity//FA i Purity//FB