"value":"A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-1188 Insecure Default Initialization of Resource",
"cweId":"CWE-1188"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Pure Storage",
"product":{
"product_data":[
{
"product_name":"FlashArray",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_name":"6.3.0",
"version_value":"6.3.14"
},
{
"version_affected":"<=",
"version_name":"6.4.0",
"version_value":"6.4.10"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"url":"https://purestorage.com/security",
"refsource":"MISC",
"name":"https://purestorage.com/security"
}
]
},
"generator":{
"engine":"Vulnogram 0.2.0"
},
"source":{
"discovery":"INTERNAL"
},
"solution":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"<span style=\"background-color: rgb(255, 255, 255);\">Affected customers will need to apply a self-service patch bundle or upgrade their Purity to an unaffected Purity version.\n<br>\n<br>This issue is resolved in the following<span style=\"background-color: rgb(255, 255, 255);\"> FlashArray Purity </span> releases:\n<br><ul><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.3.15 or later </span></li><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.5.1 or later </span></li><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.6.1 or later. </span></li></ul></span>"
}
],
"value":"Affected customers will need to apply a self-service patch bundle or upgrade their Purity to an unaffected Purity version.\n\n\n\nThis issue is resolved in the following\u00a0FlashArray Purity releases:\n\n * Purity//FA versions 6.3.15 or later\u00a0\n * Purity//FA versions 6.5.1 or later\u00a0\n * Purity//FA versions 6.6.1 or later."