Description
An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.
Published: 2026-07-14
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can target a Trellix HX Console running version 10.0.0 or an earlier release can craft detection payloads that trigger the console to decompress a very large file. The decompression consumes excessive CPU and memory, exhausting system resources and causing the console to become unresponsive. The weakness is a resource switch, classified by CWE‑409, and does not directly affect confidentiality or data integrity.

Affected Systems

The affected product is the Trellix HX Console, specifically versions 10.0.0 and all prior releases. Any deployment of this console that has not applied a patched version remains vulnerable.

Risk and Exploitability

The CVSS score of 6.0 shows moderate severity, while the EPSS score of < 1 % indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to gain access to the console and submit the crafted payload; the attack vector is inferred to be a local or privileged remote intrusion rather than a pure remote web exploit. Successful exploitation would render the console unavailable, disrupting security operations.

Generated by OpenCVE AI on August 1, 2026 at 09:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Trellix HX Console to a version that contains the fix for the decompression resource exhaustion vulnerability.
  • Limit the ability of users to send detection payloads to the console; restrict this capability to trusted accounts only.
  • Deploy monitoring for spikes in CPU and memory consumption on the HX console and configure alerts or automated throttling to mitigate denial‑of‑service attempts.

Generated by OpenCVE AI on August 1, 2026 at 09:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Denial of Service Due to Excessive Decompression in Trellix HX Console

Wed, 29 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Denial of Service Due to Excessive Decompression in Trellix HX Console

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Trellix
Trellix trellix Hx Console
Vendors & Products Trellix
Trellix trellix Hx Console

Fri, 24 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Denial of Service in Trellix HX Console

Mon, 20 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Resource Exhaustion Denial of Service in Trellix HX Console

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.
Weaknesses CWE-409
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Trellix Trellix Hx Console
cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2026-07-14T13:26:51.155Z

Reserved: 2026-06-18T08:34:21.001Z

Link: CVE-2026-12588

cve-icon Vulnrichment

Updated: 2026-07-14T13:26:48.364Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)