Database/Control plane, storage & DevOps
Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrative
CVSS 9.1CVE-2024-0003Control plane, storage & DevOpscurated
Impact
An attacker uses a remote administrative service to create a privileged account on the array - persistent backdoor access to the storage system.
Who can reach it
Remote network access with high privilege to the administrative service.
What to do
Apply the Purity update, then enumerate array accounts and remove any you did not create. Account review matters more than the version bump here.
References
Related entries
- Pure Storage FlashArray Purity (array admin command execution): A user holding the array admin role executes arbitraryCVE-2024-0004 · Pure Storage FlashArray Purity (array admin command execution)Critical
- Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yieldsCVE-2024-0005 · Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection)Critical
- Ivanti Connect Secure: Command injection in web componentsCVE-2024-21887 · Ivanti Connect SecureCritical
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCVE-2024-37287 · KibanaCritical
- Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4CVE-2024-53146 · Linux NFS server (nfsd, NFSv4 COMPOUND tag decode)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.