CVE-2025-9127: PX Enterprise Improper Sanitization Vulnerability
Published Dec 4, 2025
·Updated
A vulnerability exists in PX Enterprise whereby sensitive information may be logged under specific conditions.
Affected Software
6 affected components
PX Enterprise
PureStorage Portworx>=3.1.1<3.1.9
PureStorage Portworx>=3.2.0<3.2.4
PureStorage Portworx>=3.3.1<3.3.1.3
PureStorage Portworx=2.13.12
PureStorage Portworx=3.3.0
Remediation
Information
This issue is resolved in the following PX Enterprise releases:
* Portworx Enterprise 3.1.9 or later
* Portworx Enterprise 3.2.4 or later
* Portworx Enterprise 3.3.1.3 or later
Event History
Dec 4, 2025
CVE Published
via MITRE·05:59 PM
Data Sourced
via MITRE·05:59 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-9127?
CVE-2025-9127 is classified as a medium severity vulnerability due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-9127?
To mitigate CVE-2025-9127, ensure you update PX Enterprise to the latest version that addresses this vulnerability.
3
What information is affected by CVE-2025-9127?
CVE-2025-9127 may expose sensitive information logged by PX Enterprise under certain conditions.
4
Is there a workaround for CVE-2025-9127?
Currently, the recommended workaround for CVE-2025-9127 is to carefully monitor logging settings in PX Enterprise until a patch is applied.
5
When was CVE-2025-9127 reported?
CVE-2025-9127 was reported in the context of vulnerabilities affecting PX Enterprise, and its details are outlined in security advisories.