Database/Control plane, storage & DevOps
Pure Storage Purity//FA and Purity//FB management interface (exposed credential): A password for the array's management
Impact
A password for the array's management interface may be known outside Pure Storage. Anyone holding it executes arbitrary instructions on the array as root, which is total control of the storage backing the cluster.
Who can reach it
Network reach to the management interface of an affected FlashArray or FlashBlade. No legitimate account is needed, because the credential is the vulnerability.
What to do
Take the opt-in patch, apply the manual patch, or upgrade Purity//FA and Purity//FB to an unaffected release - all three routes are offered by Pure. Rotating your own admin passwords does not close this; the shipped credential has to be removed by the patch.
References
Related entries
- Brocade Fabric OS (unauthenticated remote code execution): Unauthenticated remote code execution on a Fibre ChannelCVE-2022-33186 · Brocade Fabric OS (unauthenticated remote code execution)Critical
- Fortinet FortiOS/FortiProxy: Auth bypass via an alternate pathCVE-2022-40684 · Fortinet FortiOS/FortiProxyCritical
- Fortinet FortiOS: SSL-VPN heap-based buffer overflowCVE-2022-42475 · Fortinet FortiOSCritical
- Linux NFS server (nfsd, nfssvc_decode_writeargs): The NFSv2/v3 write argument decoder has no lower bound on the lengthCVE-2022-49280 · Linux NFS server (nfsd, nfssvc_decode_writeargs)Critical
- AMD SMM Supervisor (AMD-SB-7011): The highest-scored AMD platform CVE in this database at 9.8 critical. A flaw in theCVE-2023-20596 · AMD SMM Supervisor (AMD-SB-7011)Critical
- Fortinet FortiOS / FortiProxy SSL-VPN: A heap-based buffer overflow in the SSL-VPN daemon lets a remoteCVE-2023-27997 · Fortinet FortiOS / FortiProxy SSL-VPNCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.