CVE-2023-28373
Purestorage Purity\/\/Fa 6.1.0 – 6.1.22
CVSS Score v3.1
4.4
Click a component to see what it means
Raw vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.0043
36th percentile
Summary
CVE-2023-28373 is a medium-severity an unspecified weakness vulnerability in Purestorage Purity\/\/Fa. Its CVSS base score is 4.4 (Medium).
Operationally, ranked at the 36th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-32069
Vulnerability Data
A flaw exists in FlashArray Purity whereby an array administrator by configuring an external key manager can affect the availability of data on the system including snapshots protected by SafeMode.
- CWE(s)
Related Threats
CVEs Like This One
CVE-2024-0004Same product: Purestorage Purity\/\/Fa
CVE-2024-0003Same product: Purestorage Purity\/\/Fa
CVE-2023-32572Same product: Purestorage Purity\/\/Fa
CVE-2024-0001Same product: Purestorage Purity\/\/Fa
CVE-2023-36628Same product: Purestorage Purity\/\/Fa
CVE-2024-0002Same product: Purestorage Purity\/\/Fa
CVE-2024-0005Same product: Purestorage Purity\/\/Fa
CVE-2023-36627Same vendor: Purestorage
CVE-2023-28372Same vendor: Purestorage
CVE-2023-31042Same vendor: Purestorage
Affected Assets
purestorage
purity\/\/fa
6.4.0 · 6.1.0 — 6.1.22 · 6.2.0 — 6.2.15 · 6.3.0 — 6.3.6
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.