CVE-2023-36628: Privilege Escalation in VASA
Published Oct 2, 2023
·Updated
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
Affected Software
2 affected components
PureStorage Purity\/\/fa>=6.1.0<=6.3.11
PureStorage Purity\/\/fa>=6.4.0<=6.4.5
Remediation
Information
This issue is resolved in FlashArray Purity (OE) versions 6.3.12 and later, 6.4.6 and later.
Event History
Oct 2, 2023
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-36628?
CVE-2023-36628 is a vulnerability that allows users with vSphere/ESXi VMware admin access on a FlashArray to gain root access through privilege escalation.
2
What is the severity of CVE-2023-36628?
CVE-2023-36628 has a severity of 8.8, which is considered high.
3
Which software versions are affected by CVE-2023-36628?
Versions 6.1.0 to 6.3.11 and versions 6.4.0 to 6.4.5 of Pure Storage's Purity//FA software are affected by CVE-2023-36628.
4
How can users exploit CVE-2023-36628?
Users with vSphere/ESXi VMware admin access on a FlashArray can exploit CVE-2023-36628 to gain root access through privilege escalation.
5
How can I fix CVE-2023-36628?
To fix CVE-2023-36628, users should apply the necessary software patches or upgrades provided by Pure Storage.