Database/Control plane, storage & DevOps
Pure Storage FlashBlade authentication input validation: The FlashBlade equivalent of the FlashArray pre-authentication
Impact
The FlashBlade equivalent of the FlashArray pre-authentication denial of service: malformed authentication input stops the array serving data. For a fleet using FlashBlade as the shared training filesystem, that is a full stall.
Who can reach it
Network reach to the FlashBlade authentication surface, no credentials needed. Attack complexity is rated high, so it is not trivially repeatable, but it needs no account.
What to do
Upgrade Purity//FB to the fixed release in Pure's security bulletin, and restrict network exposure of the login endpoints in the meantime.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.