Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (privileged remote access account): An attacker uses a privileged account to gain remote
CVSS 10.0CVE-2024-0002Control plane, storage & DevOpscurated
Impact
An attacker uses a privileged account to gain remote access to the array, with scope change - complete compromise of the storage tier.
Who can reach it
Remote network access to the array. No prior credentials.
What to do
Apply the Purity update from Pure's security page as a priority; this one is unauthenticated. Non-disruptive controller upgrade on healthy arrays.
References
Related entries
- Arista CloudVision Portal (on-premise): An authenticated CloudVision user can take actions on managed EOS devices wellCVE-2024-11186 · Arista CloudVision Portal (on-premise)Critical
- ConnectWise ScreenConnect: Auth bypass via alternate pathCVE-2024-1709 · ConnectWise ScreenConnectCritical
- Intel Neural Compressor: An unauthenticated user can reach an input-validation failure in Neural CompressorCVE-2024-22476 · Intel Neural CompressorCritical
- Palo Alto PAN-OS: GlobalProtect arbitrary file creationCVE-2024-3400 · Palo Alto PAN-OSCritical
- GitLab (ruby-saml): Ruby-SAML does not properly verify the SAML Response signatureCVE-2024-45409 · GitLab (ruby-saml)Critical
- Gitea: Stored cross-site scripting in Gitea 1.22.0CVE-2024-6886 · GiteaCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.