CVE-2025-0617
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.
MEDIUM · CVSS 5.9
EPSS 0.00716
Monitor
- No active-exploitation, high-EPSS, or public-exploit signals - routine patching cadence
Sigma rules0
YARA rules0