CVE-2024-3057: Purestorage Flasharray

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw exists whereby a user can make a specific call to a FlashArray endpoint allowing privilege escalation.

Affected products

  • Purestorage Flasharray: from 6.6.2, up to and including 6.6.5

Published 2024-10-08. Last modified 2026-06-17.