Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (dormant configuration account): A local account intended only for initial array
Impact
A local account intended only for initial array configuration stays active, letting an attacker gain elevated privileges on the array. Full control of a storage array serving an AI cluster means access to training data and checkpoints, plus the ability to destroy them.
Who can reach it
Network access to the array management interface, using the leftover account.
What to do
Apply the Purity update from Pure's security page. Array software upgrade - non-disruptive on a healthy dual-controller array, but schedule it. Verify the configuration account is actually disabled afterwards rather than trusting the version number.
References
Related entries
- Pure Storage FlashArray Purity (privileged remote access account): An attacker uses a privileged account to gain remoteCVE-2024-0002 · Pure Storage FlashArray Purity (privileged remote access account)Critical
- Arista CloudVision Portal (on-premise): An authenticated CloudVision user can take actions on managed EOS devices wellCVE-2024-11186 · Arista CloudVision Portal (on-premise)Critical
- ConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709 · ConnectWise ScreenConnectCritical
- Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural CompressorCVE-2024-22476 · Intel Neural CompressorCritical
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCVE-2024-3400 · Palo Alto PAN-OSCritical
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCVE-2024-45409 · GitLab (ruby-saml)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.