A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.
The product initializes or sets a resource with a default that is intended to be changed by the product’s installer, administrator, or maintainer, but the default is not secure.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Purity//fa | Purestorage | 6.3.0 (including) | 6.3.14 (including) |
| Purity//fa | Purestorage | 6.4.0 (including) | 6.4.10 (including) |