"value":"A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-269 Improper Privilege Management",
"cweId":"CWE-269"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"PureStorage",
"product":{
"product_data":[
{
"product_name":"FlashArray",
"version":{
"version_data":[
{
"version_affected":"<=",
"version_name":"5.3.17",
"version_value":"5.3.21"
},
{
"version_affected":"<=",
"version_name":"6.1.8",
"version_value":"6.1.25"
},
{
"version_affected":"<=",
"version_name":"6.0.7",
"version_value":"6.0.9"
},
{
"version_affected":"<=",
"version_name":"6.2.0",
"version_value":"6.2.17"
},
{
"version_affected":"<=",
"version_name":"6.3.0",
"version_value":"6.3.14"
},
{
"version_affected":"<=",
"version_name":"6.4.0",
"version_value":"6.4.10"
},
{
"version_affected":"=",
"version_value":"6.5.0"
}
]
}
}
]
}
}
]
}
},
"references":{
"reference_data":[
{
"url":"https://purestorage.com/security",
"refsource":"MISC",
"name":"https://purestorage.com/security"
}
]
},
"generator":{
"engine":"Vulnogram 0.2.0"
},
"source":{
"discovery":"INTERNAL"
},
"solution":[
{
"lang":"en",
"supportingMedia":[
{
"base64":false,
"type":"text/html",
"value":"Affected customers will need to apply a self-service patch bundle or upgrade their Purity to an unaffected Purity version.\n<br>\n<br>This issue is resolved in the following<span style=\"background-color: rgb(255, 255, 255);\"> FlashArray Purity </span> releases:\n<br><ul><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.3.15 or later </span></li><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.5.1 or later </span></li><li><span style=\"background-color: rgb(255, 255, 255);\">Purity//FA versions 6.6.1 or later.</span></li></ul>"
}
],
"value":"Affected customers will need to apply a self-service patch bundle or upgrade their Purity to an unaffected Purity version.\n\n\n\nThis issue is resolved in the following\u00a0FlashArray Purity releases:\n\n * Purity//FA versions 6.3.15 or later \n * Purity//FA versions 6.5.1 or later \n * Purity//FA versions 6.6.1 or later."