CVE-2023-36627

A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*
cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*
cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 2.7
v2 : unknown
v3 : 7.7
References () https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627 - Vendor Advisory () https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627 - Vendor Advisory

05 Oct 2023, 15:39

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.7
References (MISC) https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627 - (MISC) https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_for_FlashBlade_Snapshot_Scheduler_CVE-2023-36627 - Vendor Advisory
CPE cpe:2.3:a:purestorage:purity:*:*:*:*:*:*:*:*
First Time Purestorage purity
Purestorage

02 Oct 2023, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-10-02 23:15

Updated : 2024-11-21 08:10


NVD link : CVE-2023-36627

Mitre link : CVE-2023-36627

CVE.ORG link : CVE-2023-36627


JSON object : View

Products Affected

purestorage

  • purity