Back to Database
Status published
Critical
CVE-2023-4976
FlashBlade Authentication Mechanism Vulnerability
Vulnerability Description
A flaw exists in FlashBlade whereby a local account is permitted to authenticate to the management interface using an unintended method that allows an attacker to gain privileged access to the array.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4976
Credits & Attribution
No credits recorded in the NVD database.
References
More from PureStorage
View All →CVE-2024-3057
A flaw exists whereby a user can make a specific...
Critical
9.8
CVE-2024-0005
A condition exists in FlashArray and FlashBlade Purity whereby a...
Critical
9.1
CVE-2024-0004
A condition exists in FlashArray Purity whereby an user with...
Critical
9.1
CVE-2024-0003
A condition exists in FlashArray Purity whereby a malicious user...
Critical
9.1
CVE-2024-0002
A condition exists in FlashArray Purity whereby an attacker can...
Critical
10
Affected Vendor
PureStorage
View all reports →Affected Software
FlashBlade
Vulnerable Versions:
3.3.5, 4.0.4, 4.1.0, 4.2.0
Timeline
Official Publish:
July 17th, 2024
Last Modified:
April 10th, 2025
Added to House:
July 22nd, 2026