CRITICAL🇵🇱 Wersja polska

CVE-2024-0005

CVSS 9.1v3.1pub. 2024-09-23upd. 2024-09-27

A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.

🤖 AI Analysis
How it works

An attacker with administrative privileges can deliver a specially crafted SNMP configuration that leads to execution of arbitrary system commands on the device. The vulnerability results from insufficient validation or sanitization of input data passed in the SNMP configuration (CWE-77: Improper Neutralization of Special Elements used in a Command). The attack vector is network-based, does not require user interaction, and the impact includes a different system scope (Scope: Changed).

Impact

Successful exploitation of the vulnerability allows an attacker to remotely execute arbitrary commands with potential takeover of full device control, resulting in loss of confidentiality, integrity, and availability of data and system.

Mitigation & patch

Apply patches available from the manufacturer according to references published at https://purestorage.com/security. Additionally, it is recommended to restrict administrative access to device management interfaces and control access to SNMP configuration only to trusted hosts.

Who is affected

Pure Storage Purity//FA (FlashArray) and Purity//FB (FlashBlade) — specific versions indicated in manufacturer references (https://purestorage.com/security)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Purestorage Purity\/\/fa

    APP
    Purestorage
    6.5.06.6.05.2.0 – 5.2.75.3.0 – 5.3.216.0.0 – 6.0.96.1.0 – 6.1.256.2.0 – 6.2.176.3.0 – 6.3.146.4.0 – 6.4.105.0.0 – 5.0.115.1.0 – 5.1.17
  • Purestorage Purity\/\/fb

    APP
    Purestorage
    4.3.04.3.13.2.0 – 3.2.103.3.0 – 3.3.113.0.0 – 3.0.94.1.0 – 4.1.104.2.0 – 4.2.34.0.0 – 4.0.63.1.0 – 3.1.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-0001CRITICAL10.0PL ✓same product

FlashArray Purity — aktywne konto lokalne umożliwia privilege escalation

CVE-2024-0004CRITICAL9.1PL ✓same product

Zdalne wykonanie kodu z eskalacją uprawnień w Pure Storage FlashArray Purity

CVE-2024-0003CRITICAL9.1PL ✓same product

Pure Storage FlashArray Purity — nieautoryzowane tworzenie konta z uprawnieniami

CVE-2024-0002CRITICAL10.0PL ✓same product

Obejście uwierzytelnienia w Pure Storage FlashArray Purity (CVSS 10.0)

CVE-2022-32554CRITICAL9.8PL ✓same product

Ujawnione dane uwierzytelniające w Pure Storage Purity//FA i Purity//FB