An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://thrive.trellix.com/s/article/000014214 |
|
History
Wed, 29 Jan 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service. | |
| Weaknesses | CWE-776 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: trellix
Published: 2025-01-29T10:08:29.476Z
Updated: 2025-02-12T19:51:14.817Z
Reserved: 2025-01-21T12:54:01.333Z
Link: CVE-2025-0617
No data.
Status : Received
Published: 2025-01-29T11:15:09.330
Modified: 2025-01-29T11:15:09.330
Link: CVE-2025-0617
No data.