An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://thrive.trellix.com/s/article/000014214 |
![]() ![]() |
History
Wed, 29 Jan 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service. | |
Weaknesses | CWE-776 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2025-02-12T19:51:14.817Z
Reserved: 2025-01-21T12:54:01.333Z
Link: CVE-2025-0617

No data.

Status : Received
Published: 2025-01-29T11:15:09.330
Modified: 2025-01-29T11:15:09.330
Link: CVE-2025-0617

No data.