Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-36627— FlashBlade Snapshot Scheduler

CVSS 7.7 · High EPSS 0.04% · P11
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-36627

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FlashBlade Snapshot Scheduler
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pure Storage FlashBlade 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pure Storage FlashBlade是美国Pure Storage公司的一个用于文件和对象工作负载的整合存储平台。 FlashBlade Purity存在安全漏洞,该漏洞源于有权访问配置了与时区相关的快照计划的 FlashBlade 上的管理帐户的用户可以配置时区以阻止计划正常运行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Pure StorageFlashBlade Purity 0 ~ 3.3.7 -

II. Public POCs for CVE-2023-36627

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-36627

登录查看更多情报信息。

Same Patch Batch · Pure Storage · 2023-10-02 · 6 CVEs total

CVE-2023-366288.8 HIGHPrivilege Escalation in VASA
CVE-2023-310427.7 HIGHFlashBlade Object Store Protocol
CVE-2023-283726.5 MEDIUMFlashBlade Object Store Privileged Access
CVE-2023-325726.5 MEDIUMFlashArray pgroup Retention Lock SafeMode Protection
CVE-2023-283734.4 MEDIUMFlashArray SafeMode Immutable Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2023-36627

No comments yet


Leave a comment