CVE-2022-32554: Critical severity pure storage purity vulnerability
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are vulnerable to possibly exposed credentials for accessing the product’s management interface. The password may be known outside Pure Storage and could be used on an affected system, if reachable, to execute arbitrary instructions with root privileges. No other Pure Storage products or services are affected. Remediation is available from Pure Storage via a self-serve “opt-in” patch, manual patch application or a software upgrade to an unaffected version of Purity software.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32554?
The severity of CVE-2022-32554 is critical with a score of 9.8.
Which Pure Storage products are affected by CVE-2022-32554?
Pure Storage FlashArray products running Purity//FA 6.2.0 - 6.2.3, 6.1.0 - 6.1.12, 6.0.0 - 6.0.8, 5.3.0 - 5.3.17, 5.2.x and prior Purity//FA releases, and Pure Storage FlashBlade products running Purity//FB 3.3.0, 3.2.0 - 3.2.4, 3.1.0 - 3.1.12, 3.0.x and prior Purity//FB releases are affected.
How can I fix CVE-2022-32554?
To fix CVE-2022-32554, it is recommended to apply the security update provided by Pure Storage. Please refer to the official security advisory for more details.
Where can I find more information about CVE-2022-32554?
You can find more information about CVE-2022-32554 in the official security advisory provided by Pure Storage.