Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-0005

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
Attacker Value
Unknown

CVE-2024-0004

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
Attacker Value
Unknown

CVE-2024-0003

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
Attacker Value
Unknown

CVE-2024-0002

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
Attacker Value
Unknown

CVE-2024-0001

Disclosure Date: September 23, 2024 (last updated September 28, 2024)
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
Attacker Value
Unknown

CVE-2024-43348

Disclosure Date: August 18, 2024 (last updated August 19, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Iznyn Purity Of Soul allows Reflected XSS.This issue affects Purity Of Soul: from n/a through 1.9.
0
Attacker Value
Unknown

CVE-2023-36628

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
Attacker Value
Unknown

CVE-2023-32572

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.
Attacker Value
Unknown

CVE-2023-28373

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode.
Attacker Value
Unknown

CVE-2023-36627

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.