CVE-2025-0254
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
20/03/2025
Last modified:
20/03/2025
Description
HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM