CVE-2023-32572: FlashArray pgroup Retention Lock SafeMode Protection
Published Oct 2, 2023
·Updated
A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.
Affected Software
2 affected components
PureStorage Purity\/\/fa>=6.3.0<=6.3.7
PureStorage Purity\/\/fa>=6.4.0<=6.4.1
Remediation
Information
This issue is resolved in FlashArray Purity (OE) versions 6.3.8 and later, 6.4.3 and later.
Event History
Oct 2, 2023
CVE Published
via MITRE·11:09 PM
Data Sourced
via MITRE·11:09 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2023-32572.
2
What is the severity level of CVE-2023-32572?
The severity level of CVE-2023-32572 is medium with a severity value of 4.9.
3
What software is affected by CVE-2023-32572?
The affected software is Pure Storage FlashArray Purity version 6.3.0 to 6.3.7 and version 6.4.0 to 6.4.1.
4
What is the impact of this vulnerability?
This vulnerability allows an array administrator to alter the retention lock of a pgroup and disable pgroup SafeMode protection.
5
Is there a fix available for CVE-2023-32572?
Yes, it is recommended to update to the latest version of Pure Storage FlashArray Purity to address this vulnerability.