Database/Control plane, storage & DevOps
Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yields
CVSS 9.1CVE-2024-0005Control plane, storage & DevOpscurated
Impact
A crafted SNMP configuration yields arbitrary remote command execution on the array. Affects FlashBlade too, which is the platform commonly used for AI training data lakes.
Who can reach it
Authenticated high-privilege user able to set SNMP configuration.
What to do
Apply the Purity update, and audit existing SNMP configuration on arrays for injected content - the payload persists in configuration across the upgrade.
References
Related entries
- Ivanti Connect Secure: Command injection in web componentsCVE-2024-21887 · Ivanti Connect SecureCritical
- Zabbix: Unsanitized clientip in the audit logCVE-2024-22120 · ZabbixCritical
- Kibana: Prototype pollution via ML/Alerting connectors + write access to internal ML indicesCVE-2024-37287 · KibanaCritical
- Linux NFS server (nfsd, NFSv4 COMPOUND tag decode): An NFSv4 COMPOUND tag length near U32_MAX overflows the length+4CVE-2024-53146 · Linux NFS server (nfsd, NFSv4 COMPOUND tag decode)Critical
- GitHub Enterprise Server: Improper signature verificationCVE-2024-9487 · GitHub Enterprise ServerCritical
- Palo Alto PAN-OS: Management web interface auth bypass invoking PHP scriptsCVE-2025-0108 · Palo Alto PAN-OSCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.