Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pure Storage, Inc.

First CVE: Oct 11, 2017Active for: 9 yearsTotal CVEs: 17
30.2
VTI Score
Low

Pure Storage, Inc. develops enterprise storage platforms and container orchestration software that handle mission-critical data infrastructure, with its vulnerability footprint concentrated in a focused product line including Purity operating systems, Portworx, and related management tools. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through access-control, authentication, and privilege-management weakness classes that reflect the sensitivity of administrative and data-access boundaries in storage systems. Defenders should prioritize patching in this vendor's infrastructure tier; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pure Storage, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 11, 2017
8 years ago
Most Recent CVE
Dec 4, 2025
233 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-0001CRITICAL
A condition exists in FlashArray Purity whereby a local account intended for initial array configuration remains active potentially allowing a malicious actor to gain elevated priv
Sep 23, 20249.832NONO
CVE-2024-0002CRITICAL
A condition exists in FlashArray Purity whereby an attacker can employ a privileged account allowing remote access to the array.
Sep 23, 20249.831NONO
CVE-2022-32554CRITICAL
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p
Jun 23, 20229.831NONO
CVE-2024-0005HIGH
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
Sep 23, 20248.830NONO
CVE-2022-31524CRITICAL
The PureStorage-OpenConnect/swagger repository through 1.1.5 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Jul 11, 20229.328NONO
CVE-2022-32553HIGH
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p
Jun 23, 20228.827NONO
CVE-2022-32552HIGH
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade p
Jun 23, 20228.827NONO
CVE-2023-36628HIGH
A flaw exists in VASA which allows users with access to a vSphere/ESXi VMware admin on a FlashArray to gain root access through privilege escalation.
Oct 3, 20238.826NONO
CVE-2024-0004HIGH
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
Sep 23, 20247.225NONO
CVE-2024-0003HIGH
A condition exists in FlashArray Purity whereby a malicious user could use a remote administrative service to create an account on the array allowing privileged access.
Sep 23, 20247.225NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
18%
24%
35%
24%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (5.9%)
Network16 (94.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low7 (41.2%)
High6 (35.3%)
None4 (23.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pure Storage, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pure Storage, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pure Storage, Inc.'s Products

View all 2 CNAs →

Top CWEs