CVE-2024-0005: Command Injection
Published Sep 23, 2024
·Updated
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
Affected Software
20 affected components
PureStorage Purity\/\/fa>=5.0.0<=5.0.11
PureStorage Purity\/\/fa>=5.1.0<=5.1.17
PureStorage Purity\/\/fa>=5.2.0<=5.2.7
PureStorage Purity\/\/fa>=5.3.0<=5.3.21
PureStorage Purity\/\/fa>=6.0.0<=6.0.9
PureStorage Purity\/\/fa>=6.1.0<=6.1.25
PureStorage Purity\/\/fa>=6.2.0<=6.2.17
PureStorage Purity\/\/fa>=6.3.0<=6.3.14
PureStorage Purity\/\/fa>=6.4.0<=6.4.10
PureStorage Purity\/\/fa=6.5.0
PureStorage Purity\/\/fa=6.6.0
PureStorage Purity\/\/fb>=3.0.0<=3.0.9
PureStorage Purity\/\/fb>=3.1.0<=3.1.5
PureStorage Purity\/\/fb>=3.2.0<=3.2.10
PureStorage Purity\/\/fb>=3.3.0<=3.3.11
PureStorage Purity\/\/fb>=4.0.0<=4.0.6
PureStorage Purity\/\/fb>=4.1.0<=4.1.10
PureStorage Purity\/\/fb>=4.2.0<=4.2.3
PureStorage Purity\/\/fb=4.3.0
PureStorage Purity\/\/fb=4.3.1
Remediation
Information
Affected customers will need to apply a self-service patch bundle or upgrade their Purity to an unaffected Purity version.
This issue is resolved in the following FlashArray Purity releases:
* Purity//FA versions 6.3.15 or later
* Purity//FA versions 6.5.1 or later
* Purity//FA versions 6.6.1 or later.
This issue is resolved in the following FlashBlade Purity releases:
* Purity//FB versions 4.1.12 or later
* Purity//FB versions 4.3.2 or later
Event History
Sep 23, 2024
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-0005?
CVE-2024-0005 is classified with a severity that allows remote command execution.
2
How do I fix CVE-2024-0005?
To fix CVE-2024-0005, you should update to the latest version of PureStorage Purity available from the vendor.
3
What systems are affected by CVE-2024-0005?
CVE-2024-0005 affects various versions of PureStorage Purity for both FlashArray and FlashBlade.
4
Can CVE-2024-0005 be exploited remotely?
Yes, CVE-2024-0005 can be exploited remotely through a specially crafted SNMP configuration.
5
What type of attack does CVE-2024-0005 enable?
CVE-2024-0005 enables a malicious user to execute arbitrary commands on the affected systems.