CVE-2025-0257

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 2, 2025
Updated: Apr 10, 2025
CWE ID 306

Summary

CVE-2025-0257 is a vulnerability affecting HCL DevOps Deploy and HCL Launch. It arises from the absence of authentication in the Agent Relay service, which could potentially enable unauthorized access to other services and expose sensitive data. An attacker could exploit this issue to gain unauthorized access to protected resources, compromising the security of the affected systems. Organizations using these HCL products are advised to apply the necessary patches or updates to mitigate this risk. Failure to do so could result in serious data breaches or unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share