GPU VulnDB

Database/Control plane, storage & DevOps

Pure Storage FlashArray Purity (privileged remote access account): An attacker uses a privileged account to gain remote

CVE-2024-0002Control plane, storage & DevOpscurated

Impact

An attacker uses a privileged account to gain remote access to the array, with scope change - complete compromise of the storage tier.

Who can reach it

Remote network access to the array. No prior credentials.

What to do

Apply the Purity update from Pure's security page as a priority; this one is unauthenticated. Non-disruptive controller upgrade on healthy arrays.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.