CVE Vulnerabilities

CVE-2023-32572

Published: Oct 03, 2023 | Modified: Oct 05, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw exists in FlashArray Purity wherein under limited circumstances, an array administrator can alter the retention lock of a pgroup and disable pgroup SafeMode protection.

Affected Software

Name Vendor Start Version End Version
Purity//fa Purestorage 6.3.0 (including) 6.3.7 (including)
Purity//fa Purestorage 6.4.0 (including) 6.4.1 (including)

References

  • https://https://support.purestorage.com/Pure_Storage_Technical_Services/Field_Bulletins/Security_Bulletins/Security_Bulletin_-_FlashArray_pgroup_Retention_Lock_SafeMode_Protection_CVE-2023-32572