VYPR

HX

by Trellix

CVEs (2)

  • CVE-2025-0617MedJan 29, 2025
    risk 0.38cvss 5.9epss 0.00

    An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.

  • CVE-2026-12588MedJul 14, 2026
    risk 0.00cvss epss 0.00

    An attacker with access to an HX 10.0.0  and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger decompression of a large file that consumes an excessive amount of system resources thus causing a Denial of Service.