Sensitive Information Exposure in PX Enterprise by Pure Storage
CVE-2025-9127

8.4HIGH

Key Information:

Vendor
CVE Published:
4 December 2025

What is CVE-2025-9127?

A vulnerability has been identified in PX Enterprise, a product by Pure Storage, where under particular conditions sensitive information may be inadvertently logged. This risk can potentially lead to unauthorized access to confidential data, requiring immediate attention and remediation to protect sensitive information and maintain data integrity.

Affected Version(s)

PX Enterprise 3.3.0, 3.3.1, 3.3.1.1, 3.3.1.2

PX Enterprise 3.2.0, 3.2.1, 3.2.2, 3.2.3

PX Enterprise 3.1.1 <= 3.1.8

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9127 : Sensitive Information Exposure in PX Enterprise by Pure Storage