CVE-2024-0005
- EPSS 0.36%
- Veröffentlicht 23.09.2024 18:15:05
- Zuletzt bearbeitet 27.09.2024 15:25:40
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
CVE-2024-0001
- EPSS 2.26%
- Veröffentlicht 23.09.2024 18:15:04
- Zuletzt bearbeitet 27.09.2024 14:08:57
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
CVE-2024-0002
- EPSS 0.6%
- Veröffentlicht 23.09.2024 18:15:04
- Zuletzt bearbeitet 27.09.2024 14:13:24
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
CVE-2024-0003
- EPSS 0.36%
- Veröffentlicht 23.09.2024 18:15:04
- Zuletzt bearbeitet 27.09.2024 14:23:58
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
CVE-2024-0004
- EPSS 0.47%
- Veröffentlicht 23.09.2024 18:15:04
- Zuletzt bearbeitet 27.09.2024 14:24:41
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
CVE-2023-36628
- EPSS 0.17%
- Veröffentlicht 03.10.2023 00:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:06
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
CVE-2023-28373
- EPSS 0.04%
- Veröffentlicht 03.10.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 07:54:56
A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode.
CVE-2023-32572
- EPSS 0.04%
- Veröffentlicht 03.10.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:03:37
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.
- EPSS 0.54%
- Veröffentlicht 23.06.2022 17:15:13
- Zuletzt bearbeitet 21.11.2024 07:06:36
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x...
- EPSS 0.54%
- Veröffentlicht 23.06.2022 17:15:13
- Zuletzt bearbeitet 21.11.2024 07:06:37
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x...