Back

CRITICAL

FlashBlade Authentication Mechanism Vulnerability

Published Jul 17, 2024

Description

A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.

Affected products

Remediation

Vendor solution

This vulnerability can be fixed either by applying a patch or upgrading to an unaffected Purity version.

This issue is resolved in the following FlashBlade Purity versions:

* Purity//FB 3.3.11 or later

* Purity//FB 4.1.9 or later

* Purity//FB 4.2.3 or later

* Purity//FB 4.3.0 or later

* Purity//FB 4.4.0 or later

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PureStorage
Published Jul 17, 2024
Updated Apr 10, 2025
Reserved Sep 14, 2023
CISA Vulnrichment
Updated Jul 17, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner PureStorage
Published Jul 17, 2024
Updated Apr 10, 2025
Exploited since n/a
EUVD-2023-54812