FlashBlade Authentication Mechanism Vulnerability
Published Jul 17, 2024
9.3
CRITICALCVSS 4.0
EPSS 0.38%
Description
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
Affected products
-
- Version 3.3.5StatusaffectedConstraints<=3.3.10
- Version 4.0.4StatusaffectedConstraints<=4.0.6
- Version 4.1.0StatusaffectedConstraints<=4.1.8
- Version 4.2.0StatusaffectedConstraints<=4.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| PureStorage | FlashBlade | unaffected |
|
No data.
-
- Version 3.3.5StatusaffectedConstraints<=3.3.10
- Version 4.0.4StatusaffectedConstraints<=4.0.6
- Version 4.1.0StatusaffectedConstraints<=4.1.8
- Version 4.2.0StatusaffectedConstraints<=4.2.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Purestorage | Flashblade | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This vulnerability can be fixed either by applying a patch or upgrading to an unaffected Purity version.
This issue is resolved in the following FlashBlade Purity versions:
* Purity//FB 3.3.11 or later
* Purity//FB 4.1.9 or later
* Purity//FB 4.2.3 or later
* Purity//FB 4.3.0 or later
* Purity//FB 4.4.0 or later
References (3)
Change history (0)
No recorded changes yet.