A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
An authenticated user with the array admin role can send specially crafted commands to the FlashArray Purity system over the network, without requiring interaction from other users. The vulnerability is classified as CWE-94 (code injection), meaning the system fails to properly neutralize input data before interpreting it as code. This results in the possibility of privilege escalation beyond the level granted to the array admin role, potentially to the system level on the storage array.
An attacker with array admin privileges can escalate their privileges on the device and gain full control over the FlashArray storage array, creating a risk of breach of confidentiality, integrity, and availability of stored data.
Apply patches available from the vendor in accordance with references published on https://purestorage.com/security. Additionally, it is recommended to restrict access to accounts with the array admin role only to trusted and necessary users and to monitor administrative activity on FlashArray devices.
Pure Storage FlashArray Purity — versions indicated in vendor references (https://purestorage.com/security)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HPurestorage Purity\/\/fa
APPPurestorage6.5.05.1.0 – 5.1.175.2.0 – 5.2.75.3.0 – 5.3.216.0.0 – 6.0.95.0.0 – 5.0.116.2.0 – 6.2.176.3.0 – 6.3.146.4.0 – 6.4.106.1.0 – 6.1.25
Related vulnerabilities
FlashArray Purity — aktywne konto lokalne umożliwia privilege escalation
Command injection w Pure Storage Purity poprzez konfigurację SNMP
Pure Storage FlashArray Purity — nieautoryzowane tworzenie konta z uprawnieniami
Obejście uwierzytelnienia w Pure Storage FlashArray Purity (CVSS 10.0)
Ujawnione dane uwierzytelniające w Pure Storage Purity//FA i Purity//FB