CRITICAL🇵🇱 Wersja polska

CVE-2024-0004

CVSS 9.1v3.1pub. 2024-09-23upd. 2024-09-27

A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.

🤖 AI Analysis
How it works

An authenticated user with the array admin role can send specially crafted commands to the FlashArray Purity system over the network, without requiring interaction from other users. The vulnerability is classified as CWE-94 (code injection), meaning the system fails to properly neutralize input data before interpreting it as code. This results in the possibility of privilege escalation beyond the level granted to the array admin role, potentially to the system level on the storage array.

Impact

An attacker with array admin privileges can escalate their privileges on the device and gain full control over the FlashArray storage array, creating a risk of breach of confidentiality, integrity, and availability of stored data.

Mitigation & patch

Apply patches available from the vendor in accordance with references published on https://purestorage.com/security. Additionally, it is recommended to restrict access to accounts with the array admin role only to trusted and necessary users and to monitor administrative activity on FlashArray devices.

Who is affected

Pure Storage FlashArray Purity — versions indicated in vendor references (https://purestorage.com/security)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Purestorage Purity\/\/fa

    APP
    Purestorage
    6.5.05.1.0 – 5.1.175.2.0 – 5.2.75.3.0 – 5.3.216.0.0 – 6.0.95.0.0 – 5.0.116.2.0 – 6.2.176.3.0 – 6.3.146.4.0 – 6.4.106.1.0 – 6.1.25
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-0001CRITICAL10.0PL ✓same product

FlashArray Purity — aktywne konto lokalne umożliwia privilege escalation

CVE-2024-0005CRITICAL9.1PL ✓same product

Command injection w Pure Storage Purity poprzez konfigurację SNMP

CVE-2024-0003CRITICAL9.1PL ✓same product

Pure Storage FlashArray Purity — nieautoryzowane tworzenie konta z uprawnieniami

CVE-2024-0002CRITICAL10.0PL ✓same product

Obejście uwierzytelnienia w Pure Storage FlashArray Purity (CVSS 10.0)

CVE-2022-32554CRITICAL9.8PL ✓same product

Ujawnione dane uwierzytelniające w Pure Storage Purity//FA i Purity//FB