2023-10-02 23:55:27 +00:00
{
"id" : "CVE-2023-36627" ,
"sourceIdentifier" : "psirt@purestorage.com" ,
"published" : "2023-10-02T23:15:12.470" ,
2023-10-05 16:00:30 +00:00
"lastModified" : "2023-10-05T15:39:20.327" ,
"vulnStatus" : "Analyzed" ,
2023-10-02 23:55:27 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly. \n"
2023-10-03 14:00:28 +00:00
} ,
{
"lang" : "es" ,
"value" : "Existe una falla en FlashBlade Purity por la cual un usuario con acceso a una cuenta administrativa en un FlashBlade que est\u00e1 configurado con programas de instant\u00e1neas dependientes de la zona horaria puede configurar una zona horaria para evitar que el programa funcione correctamente."
2023-10-02 23:55:27 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2023-10-05 16:00:30 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "HIGH" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 2.7 ,
"baseSeverity" : "LOW"
} ,
"exploitabilityScore" : 1.2 ,
"impactScore" : 1.4
} ,
2023-10-02 23:55:27 +00:00
{
"source" : "psirt@purestorage.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "NONE" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "HIGH" ,
"baseScore" : 7.7 ,
"baseSeverity" : "HIGH"
} ,
"exploitabilityScore" : 3.1 ,
"impactScore" : 4.0
}
]
} ,
2023-10-05 16:00:30 +00:00
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*" ,
"versionEndIncluding" : "3.3.7" ,
"matchCriteriaId" : "D1C0F497-DD08-458D-880A-6F28D43EAA65"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.0.0" ,
"versionEndIncluding" : "4.0.5" ,
"matchCriteriaId" : "3742D7B1-35C9-411A-95E5-694631B7314E"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "4.1.0" ,
"versionEndIncluding" : "4.1.2" ,
"matchCriteriaId" : "74E272AA-D989-45ED-881E-6F05EDE1C255"
}
]
}
]
}
] ,
2023-10-02 23:55:27 +00:00
"references" : [
{
"url" : "https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627" ,
2023-10-05 16:00:30 +00:00
"source" : "psirt@purestorage.com" ,
"tags" : [
"Vendor Advisory"
]
2023-10-02 23:55:27 +00:00
}
]
}