CVE-2025-2327 Overview
CVE-2025-2327 is an information disclosure vulnerability in Pure Storage FlashArray. The flaw causes the Key Encryption Key (KEK) to be written to system logs during key rotation when Rapid Data Locking (RDL) is configured. An authenticated attacker with high privileges and access to the affected logs could recover the KEK material. Exposure of the KEK undermines the encryption key hierarchy that protects data-at-rest on the array. The weakness is categorized under [CWE-532: Insertion of Sensitive Information into Log File].
Critical Impact
Exposure of the FlashArray Key Encryption Key through log files weakens data-at-rest protections and could allow an attacker with log access to derive or misuse encryption material.
Affected Products
- Pure Storage FlashArray running configurations with Rapid Data Locking (RDL) enabled
- FlashArray software versions prior to the vendor-supplied fix (see Pure Storage Product Security advisory)
- Deployments performing KEK rotation while RDL is active
Discovery Timeline
- 2025-06-16 - CVE-2025-2327 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD
Technical Details for CVE-2025-2327
Vulnerability Analysis
The vulnerability resides in the key rotation routine used by FlashArray when Rapid Data Locking (RDL) is enabled. During rotation, the array writes the Key Encryption Key (KEK) into log output rather than restricting it to protected memory. Any actor able to read the log stream can retrieve KEK material intended to remain confidential.
The KEK sits at the top of the FlashArray key hierarchy. It wraps the Data Encryption Keys (DEKs) that encrypt tenant volumes. Recovery of the KEK reduces the effective strength of the array's data-at-rest protection. The impact is scoped to confidentiality; integrity and availability of the array are not directly affected. Exploitation requires high privileges on the network-accessible management surface, so the attack path is constrained to insiders or attackers who have already compromised an administrative identity.
Root Cause
The root cause is improper handling of sensitive material during a key management operation. Secrets that should reside only in protected memory or key stores are emitted through a general-purpose logging channel. This aligns with [CWE-532] and reflects a lack of redaction or filtering in the code path exercised by RDL-enabled key rotation.
Attack Vector
Exploitation requires an authenticated user with high privileges to trigger or observe a key rotation event on an array with RDL configured. The attacker then reads the log output containing the KEK. The vector is network-adjacent through FlashArray administrative interfaces, but access to logs, whether via the management console, exported syslog, or a downstream log aggregator, is the practical exploitation path. See the Pure Storage Product Security portal for vendor-specific technical guidance.
Detection Methods for CVE-2025-2327
Indicators of Compromise
- Log entries generated during FlashArray key rotation events that contain unexpected key material or high-entropy strings
- Access to FlashArray log exports, syslog streams, or log aggregators by accounts outside the normal administrative baseline
- Recent RDL-enabled key rotation events on arrays running vulnerable software versions
Detection Strategies
- Audit FlashArray system logs and any downstream SIEM stores for entries emitted during KEK rotation windows and flag entries containing key-like data
- Review privileged administrator activity around key rotation events, correlating array audit logs with identity provider authentication records
- Inventory log destinations that received FlashArray output before patching to determine the exposure surface
Monitoring Recommendations
- Forward FlashArray audit and system logs to a centralized data lake and alert on key rotation operations while RDL is enabled
- Monitor read access to archived FlashArray logs and restrict retrieval to a small group of accountable operators
- Track configuration changes to RDL and key rotation schedules to detect unexpected administrative actions
How to Mitigate CVE-2025-2327
Immediate Actions Required
- Apply the FlashArray Purity update referenced in the Pure Storage Product Security advisory
- Rotate the KEK on affected arrays after upgrading to fixed software so any previously logged key material is retired
- Purge or restrict access to historical logs that may contain KEK values, including copies stored in SIEM and backup systems
- Review and reduce the set of accounts with FlashArray administrative privileges
Patch Information
Pure Storage has published guidance and fixed software through its product security portal. Refer to the Pure Storage Product Security page for the specific Purity versions that remediate CVE-2025-2327 and for upgrade procedures.
Workarounds
- Defer non-essential KEK rotations on arrays with RDL enabled until the vendor patch is applied
- Restrict administrative access to FlashArray management interfaces to a hardened jump host with strong multi-factor authentication
- Limit log forwarding destinations and enforce access controls on any repository that ingests FlashArray logs
# Configuration example
# Verify Purity version and RDL status before scheduling a KEK rotation
purearray list --purity
pureconfig list | grep -i rapid-data-locking
# Do not perform: purekey rotate (until the fixed Purity version is installed)
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.