Description
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
Published: 2024-07-17
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This vulnerability can be fixed either by applying a patch or upgrading to an unaffected Purity version. This issue is resolved in the following FlashBlade Purity versions: * Purity//FB 3.3.11 or later * Purity//FB 4.1.9 or later * Purity//FB 4.2.3 or later * Purity//FB 4.3.0 or later * Purity//FB 4.4.0 or later

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-54812 A flaw exists in Purity//FB whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
History

Thu, 10 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Purestorage
Purestorage flashblade
CPEs cpe:2.3:a:purestorage:flashblade:*:*:*:*:*:*:*:*
Vendors & Products Purestorage
Purestorage flashblade
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Apr 2025 14:30:00 +0000

Type Values Removed Values Added
Description A flaw exists in Purity//FB whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array. A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
References

Subscriptions

Purestorage Flashblade
cve-icon MITRE

Status: PUBLISHED

Assigner: PureStorage

Published:

Updated: 2025-04-10T14:18:03.534Z

Reserved: 2023-09-14T20:57:21.683Z

Link: CVE-2023-4976

cve-icon Vulnrichment

Updated: 2024-08-02T07:44:53.148Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-17T16:15:03.233

Modified: 2025-04-10T15:16:01.880

Link: CVE-2023-4976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses