This page provides a list of the latest storage vulnerabilities in Pure Storage devices, and is constantly being updated.
We do our best to verify this list on a frequent basis, however if you find any inaccuracies or wish to report a potential security vulnerability for Pure Storage products, please let us know at Info@ContinuitySoftware.com.
In the meantime, if you need advice on the secure configuration or vulnerability scanning for your storage and backup systems, feel free to contact us.
Product | Risk Impact | Vulnerabilities | Details |
---|---|---|---|
FlashBlade Security Advisory | High | PURE-CVE-2023-36627: A configuration Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashBlade Security Advisory | High | PURE-CVE-2023-31042: Misconfiguration Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashBlade Security Advisory | Medium | PURE-CVE-2023-28372: Misconfiguration Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashBlade Security Advisory | High | PURE-CVE-2022-32553_B: A privilege escalation Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashBlade Security Advisory | Critical | PURE-CVE-2022-32554_B: Exposed credentials Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | Critical | PURE-CVE-2022-32554_A: Exposed credentials Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | High | PURE-CVE-2022-32553_A: Privilege escalation Vulnerabilities in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | Critical | PURE-CVE-2021-45105_A: Apache Log4j2 Vulnerabilities in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | Medium | PURE-CVE-2023-32572: pgroup Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | High | PURE-CVE-2023-36628: Privilege Escalation in VASA Vulnerability in Pure Storage Products | Link to VASA Vulnerability in Pure Storage publication |
FlashArray Security Advisory | Medium | PURE-CVE-2023-28373: SafeMode Immutable Vulnerability in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | Critical | PURE-CVE-2021-45105: Apache Log4j2 Vulnerabilities in Pure Storage Products | Link to Pure Storage publication |
FlashArray Security Advisory | High | PURE-CVE-2022-32553: Privilege escalation Vulnerabilities in Pure Storage Products | Link to Pure Storage publication | FlashArray Security Advisory | Critical | PURE-CVE-2022-32554: Exposed credentials Vulnerability in Pure Storage Products | Link to Pure Storage publication |