CVE-2023-4976
July 17, 2024, 4:15 p.m.
Tags
Product(s) Impacted
Purity//FB
Description
A flaw exists in Purity//FB whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
Weaknesses
CWE-269
Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE ID: 269Date
Published: July 17, 2024, 4:15 p.m.
Last Modified: July 17, 2024, 4:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
psirt@purestorage.com
References
https://purestorage.com/
psirt@purestorage.com