CVE-2025-0254: HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226.
Published Mar 20, 2025
·Updated
HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.
Affected Software
1 affected component
HCL Digital Experience<9.5 CF226
Event History
Mar 20, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0254?
CVE-2025-0254 is considered a high severity vulnerability as it allows attackers to potentially intercept and alter communications.
2
How do I fix CVE-2025-0254?
To fix CVE-2025-0254, upgrade HCL Digital Experience to version 9.5 CF226 or later.
3
Which components are affected by CVE-2025-0254?
CVE-2025-0254 specifically affects the Ring API and dxclient components of HCL Digital Experience.
4
What type of attack does CVE-2025-0254 facilitate?
CVE-2025-0254 facilitates man-in-the-middle (MitM) attacks, allowing interception of communications.
5
What versions of HCL Digital Experience are vulnerable to CVE-2025-0254?
HCL Digital Experience versions prior to 9.5 CF226 are vulnerable to CVE-2025-0254.