Purity\/\/faApplication · Purestorage

CVE-2024-0001

CRITICAL · 9.8 CVSS v3.1 Published 2024-09-23
Fix available
A fix is available. Upgrade to after 6.4.10 or later.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · moderate confidence

A local administrative account used for initial FlashArray Purity configuration remains active after setup instead of being disabled or removed. This creates a privilege escalation vector where an attacker with local access could exploit the leftover default credentials to gain elevated privileges on the array.

MitigationDisable or remove the local account used for initial array configuration after the setup process is complete, following Pure Storage's documented account management procedures.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Purity\/\/faApplication
Affected:>= 6.3.0, <= 6.3.14>= 6.4.0, <= 6.4.10

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Determine Purity//fa version
    Access the FlashArray management interface or use the Pure Storage CLI command to retrieve the installed Purity version. Common methods include logging into the GUI dashboard or running 'pureapp list' or similar version query commands.
    Affected if The installed version is >= 6.3.0 and <= 6.3.14, OR >= 6.4.0 and <= 6.4.10
  2. Identify local administrative accounts
    Use the Pure Storage management interface or CLI to list all local user accounts with administrative privileges. Look for accounts defined locally on the array rather than directory-integrated accounts.
    Affected if Multiple local administrative accounts exist, including the account used during initial setup that should have been disabled
  3. Verify initial setup account status
    Check whether the local administrative account created for initial FlashArray configuration is still active and enabled. This account should have been disabled or removed after setup completed.
    Affected if The default local administrative account from initial configuration remains active and usable

The environment is affected if the Purity//fa version falls within 6.3.0-6.3.14 or 6.4.0-6.4.10 AND the local administrative account from initial setup remains active on the array.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to a release after 6.4.10
Interim mitigation

Disable or remove the local account used for initial array configuration after the setup process is complete, following Pure Storage's documented account management procedures.

Recommended fix Moderate confidence

Purity//FA 6.4.11 or later (or 6.3.15 or later if remaining on the 6.3.x branch)

  1. Verify the current Purity//FA version by accessing the FlashArray management interface or using the purecli command: `purectl list version`
  2. Schedule a maintenance window for the upgrade, ensuring proper backups are in place
  3. Download the latest Purity//FA firmware from the Pure Storage Support Portal (support.purestorage.com)
  4. Upload the firmware to the FlashArray using the web interface or CLI: `purectl update /path/to/firmware.su`
  5. Monitor the upgrade process and verify the array returns to a healthy state
  6. Confirm the vulnerable local account has been disabled by reviewing local user accounts: `purectl list local-user`
  7. Verify the system is running the patched version post-upgrade
Caveat Review Pure Storage release notes for any breaking changes between current version and target version; test in non-production environment first if possible

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Purity\/\/fa Scoped from the published advisory
  • Consultation4.0 h
  • Implementation2.0 h
  • Testing3.0 h
  • Review / QA2.0 h
11.0 hours of engineering $1,970
Get the upgrade done

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $3,152.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2024-0001 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2024-0001 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data