Database/Control plane, storage & DevOps
Pure Storage Purity//FA and Purity//FB management interface (exposed credential): A password for the array's management
Impact
A password for the array's management interface may be known outside Pure Storage. Anyone holding it executes arbitrary instructions on the array as root, which is total control of the storage backing the cluster.
Who can reach it
Network reach to the management interface of an affected FlashArray or FlashBlade. No legitimate account is needed, because the credential is the vulnerability.
What to do
Take the opt-in patch, apply the manual patch, or upgrade Purity//FA and Purity//FB to an unaffected release - all three routes are offered by Pure. Rotating your own admin passwords does not close this; the shipped credential has to be removed by the patch.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.