GPU VulnDB

Database/Control plane, storage & DevOps

Pure Storage FlashArray Purity (remote administrative account creation): An attacker uses a remote administrative

CVE-2024-0003Control plane, storage & DevOpscurated

Impact

An attacker uses a remote administrative service to create a privileged account on the array - persistent backdoor access to the storage system.

Who can reach it

Remote network access with high privilege to the administrative service.

What to do

Apply the Purity update, then enumerate array accounts and remove any you did not create. Account review matters more than the version bump here.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.