← Back to browse · API

CVE-2024-0002

Severity
CRITICAL
CVSS
10.0
EPSS
0.00597
Risk score
40.21
CISA KEV
No
PoC
No
Published
2024-09-23
Modified
2024-09-23
First seen
2026-08-07
Aliases
EUVD-2024-15805, GHSA-WW64-XCQM-5JHF
Products
PureStorage:FlashArray 5.3.17 ≤5.3.21, PureStorage:FlashArray 6.0.7 ≤6.0.9, PureStorage:FlashArray 6.1.8 ≤6.1.25, PureStorage:FlashArray 6.2.0 ≤6.2.17, PureStorage:FlashArray 6.3.0 ≤6.3.14, PureStorage:FlashArray 6.4.0 ≤6.4.10, PureStorage:FlashArray 6.5.0
Sources
euvd EUVD-2024-15805

Description

A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.

References