Privilege Escalation in VASA
CVE-2023-36628
8.8HIGH
What is CVE-2023-36628?
A security flaw in VMware's VASA component allows unauthorized users with access to a vSphere/ESXi environment to escalate their privileges and potentially gain root access on Pure Storage FlashArray systems. This vulnerability poses a significant risk as it can be exploited by malicious actors to manipulate system controls, thereby compromising the integrity of the affected infrastructure.
Affected Version(s)
FlashArray Purity 6.1.*
FlashArray Purity 6.2.*
FlashArray Purity 6.3.0 <= 6.3.11