Database/Control plane, storage & DevOps
Pure Storage FlashArray / FlashBlade Purity (SNMP configuration command injection): A crafted SNMP configuration yields
CVE-2024-0005Control plane, storage & DevOpscurated
Impact
A crafted SNMP configuration yields arbitrary remote command execution on the array. Affects FlashBlade too, which is the platform commonly used for AI training data lakes.
Who can reach it
Authenticated high-privilege user able to set SNMP configuration.
What to do
Apply the Purity update, and audit existing SNMP configuration on arrays for injected content - the payload persists in configuration across the upgrade.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.