Pure Storage, Inc. develops enterprise storage platforms and container orchestration software that handle mission-critical data infrastructure, with its vulnerability footprint concentrated in a focused product line including Purity operating systems, Portworx, and related management tools. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through access-control, authentication, and privilege-management weakness classes that reflect the sensitivity of administrative and data-access boundaries in storage systems. Defenders should prioritize patching in this vendor's infrastructure tier; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pure Storage, Inc. over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-0001CRITICAL A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated priv | Sep 23, 2024 | 9.8 | 32 | NO | NO |
CVE-2024-0002CRITICAL A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array. | Sep 23, 2024 | 9.8 | 31 | NO | NO |
CVE-2022-32554CRITICAL Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p | Jun 23, 2022 | 9.8 | 31 | NO | NO |
CVE-2024-0005HIGH A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration. | Sep 23, 2024 | 8.8 | 30 | NO | NO |
CVE-2022-31524CRITICAL The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | Jul 11, 2022 | 9.3 | 28 | NO | NO |
CVE-2022-32553HIGH Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p | Jun 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-32552HIGH Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p | Jun 23, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-36628HIGH A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
| Oct 3, 2023 | 8.8 | 26 | NO | NO |
CVE-2024-0004HIGH A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array. | Sep 23, 2024 | 7.2 | 25 | NO | NO |
CVE-2024-0003HIGH A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access. | Sep 23, 2024 | 7.2 | 25 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pure Storage, Inc..
Media articles that mention a CVE ID that affects a product developed by Pure Storage, Inc. — matched by CVE ID, not by vendor name.