CVE-2025-0617

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 29, 2025
CWE ID 776

Summary

CVE-2025-0617 is a vulnerability affecting HX 10.0.0 and previous versions. An attacker with access can exploit this issue by sending malicious data to the HX console. The console, in response, performs file parsing with exponential entity expansions, leading to a Denial of Service (DoS) attack. The attacker does not require elevated privileges to execute the attack. The DoS occurs due to the resource exhaustion caused by the parsing process. This vulnerability poses a significant risk to systems running the affected HX version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share