CVE-2024-0001

CRITICAL

FlashArray Purity - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-0001.

AI-analyzed exploit summary The repository contains a Python script that checks if a given URL is vulnerable to CVE-2024-0001 by sending a GET request and verifying a 200 status code. It lacks exploit functionality and only performs basic detection.

Description

A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated privileges.

Exploits (1)

inthewild SCANNER
poc
https://github.com/jiupta/cve-2024-0001-exp

The repository contains a Python script that checks if a given URL is vulnerable to CVE-2024-0001 by sending a GET request and verifying a 200 status code. It lacks exploit functionality and only performs basic detection.

Classification
Scanner 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Unknown (CVE-2024-0001)
No auth needed
Prerequisites: target URL
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
https://purestorage.com/security

Scores

CVSS v3 10.0
EPSS 0.0220
EPSS Percentile 84.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1188
Status published
Products (1)
purestorage/purity\/\/fa 6.3.0 - 6.3.14
Published Sep 23, 2024
Tracked Since Feb 18, 2026