PT-2025-12336 · Hcl · Hcl Digital Experience

Published

2025-03-20

·

Updated

2025-03-21

·

CVE-2025-0254

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions HCL Digital Experience versions prior to 9.5 CF226
Description The issue concerns man-in-the-middle (MitM) attacks, where an attacker could intercept and potentially alter communication between two parties. This is related to the Ring API and dxclient components.
Recommendations For versions prior to 9.5 CF226, update to version 9.5 CF226 or later to resolve the issue. As a temporary workaround, consider restricting access to the Ring API and dxclient components to minimize the risk of exploitation.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0254

Affected Products

Hcl Digital Experience