CVE-2025-55275
Hcltech Aftermarket Cloud 1.0.0
Raw vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:LSummary
CVE-2025-55275 is a low-severity an unspecified weakness vulnerability in Hcltech Aftermarket Cloud. Its CVSS base score is 3.7 (Low).
Operationally, ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2025-55275 is an Admin Session Concurrency vulnerability affecting HCL Aftermarket DPC. This flaw allows an attacker to exploit concurrent sessions, enabling them to hijack or impersonate an admin user. The vulnerability is classified under CWE-557 and has a CVSS v3.1 base score of 3.7 (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L), indicating low severity with primarily confidentiality impacts.
Exploitation requires network access and low privileges (such as an authenticated low-privilege user account), but demands high attack complexity and user interaction. A successful attack could allow the adversary to impersonate an administrator through session manipulation, potentially leading to limited unauthorized access to confidential information without affecting integrity or availability.
The HCL support advisory at https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129793 provides details on mitigation and patches for this vulnerability. Security practitioners should consult this resource for specific remediation steps applicable to affected HCL Aftermarket DPC deployments.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-209073
Vulnerability Data
HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.
- CWE(s)
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.