Cyber Resilience

CVE-2023-36627

Purestorage Purity ≤ 3.3.7

Published
02 October 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 7.7
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0049 40th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2023-36627 is a high-severity an unspecified weakness vulnerability in Purestorage Purity. Its CVSS base score is 7.7 (High).

Operationally, ranked at the 40th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A flaw exists in FlashBlade Purity whereby a user with access to an administrative account on a FlashBlade that is configured with timezone-dependent snapshot schedules can configure a timezone to prevent the schedule from functioning properly.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-28372Same product: Purestorage Purity
CVE-2023-31042Same product: Purestorage Purity
CVE-2024-0004Same vendor: Purestorage
CVE-2024-0003Same vendor: Purestorage
CVE-2023-32572Same vendor: Purestorage
CVE-2024-0001Same vendor: Purestorage
CVE-2023-28373Same vendor: Purestorage
CVE-2025-9127Same vendor: Purestorage
CVE-2023-36628Same vendor: Purestorage
CVE-2024-0005Same vendor: Purestorage

Affected Assets

purestorage
purity
≤ 3.3.7 · 4.0.0 — 4.0.5 · 4.1.0 — 4.1.2

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References