A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.

Project Subscriptions

Vendors Products
Purestorage Subscribe
Portworx Subscribe
Px Enterprise Subscribe
Advisories

No advisories yet.

Fixes

Solution

This issue is resolved in the following PX Enterprise releases: * Portworx Enterprise 3.1.9 or later * Portworx Enterprise 3.2.4 or later * Portworx Enterprise 3.3.1.3 or later


Workaround

No workaround given by the vendor.

History

Tue, 03 Feb 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Purestorage portworx
CPEs cpe:2.3:a:purestorage:portworx:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:purestorage:portworx:2.13.12:*:*:*:enterprise:*:*:*
cpe:2.3:a:purestorage:portworx:3.3.0:*:*:*:enterprise:*:*:*
Vendors & Products Purestorage portworx
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Purestorage
Purestorage px Enterprise
Vendors & Products Purestorage
Purestorage px Enterprise

Thu, 04 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 04 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.
Title PX Enterprise Improper Sanitization Vulnerability
Weaknesses CWE-116
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PureStorage

Published:

Updated: 2025-12-04T20:00:49.889Z

Reserved: 2025-08-18T19:54:46.984Z

Link: CVE-2025-9127

cve-icon Vulnrichment

Updated: 2025-12-04T18:55:06.465Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-04T18:15:51.603

Modified: 2026-02-03T16:57:24.377

Link: CVE-2025-9127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-05T10:52:27Z

Weaknesses