HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.
History

Thu, 20 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 14:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-295

Thu, 20 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Description HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.
Title HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2025-03-20T15:02:17.242Z

Reserved: 2025-01-06T16:00:30.098Z

Link: CVE-2025-0254

cve-icon Vulnrichment

Updated: 2025-03-20T15:02:04.589Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-20T14:15:22.493

Modified: 2025-03-20T15:15:45.030

Link: CVE-2025-0254

cve-icon Redhat

No data.