Cyber Resilience

CVE-2025-55275

Hcltech Aftermarket Cloud 1.0.0

Published
26 March 2026
Modified
26 March 2026
Patch / advisory
CVSS Score v3.1 3.7
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L
EPSS Score 0.0022 12th percentile
Risk Priority 30 floored blend · peak EPSS

Summary

CVE-2025-55275 is a low-severity an unspecified weakness vulnerability in Hcltech Aftermarket Cloud. Its CVSS base score is 3.7 (Low).

Operationally, ranked at the 12th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2025-55275 is an Admin Session Concurrency vulnerability affecting HCL Aftermarket DPC. This flaw allows an attacker to exploit concurrent sessions, enabling them to hijack or impersonate an admin user. The vulnerability is classified under CWE-557 and has a CVSS v3.1 base score of 3.7 (AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L), indicating low severity with primarily confidentiality impacts.

Exploitation requires network access and low privileges (such as an authenticated low-privilege user account), but demands high attack complexity and user interaction. A successful attack could allow the adversary to impersonate an administrator through session manipulation, potentially leading to limited unauthorized access to confidential information without affecting integrity or availability.

The HCL support advisory at https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129793 provides details on mitigation and patches for this vulnerability. Security practitioners should consult this resource for specific remediation steps applicable to affected HCL Aftermarket DPC deployments.

EU & UK References

Vulnerability Data

HCL Aftermarket DPC is affected by Admin Session Concurrency vulnerability using which an attacker can exploit concurrent sessions to hijack or impersonate an admin user.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-55264Same product: Hcltech Aftermarket Cloud
CVE-2025-55262Same product: Hcltech Aftermarket Cloud
CVE-2025-55274Same product: Hcltech Aftermarket Cloud
CVE-2025-55268Same product: Hcltech Aftermarket Cloud
CVE-2025-55265Same product: Hcltech Aftermarket Cloud
CVE-2025-55261Same product: Hcltech Aftermarket Cloud
CVE-2025-55271Same product: Hcltech Aftermarket Cloud
CVE-2025-55269Same product: Hcltech Aftermarket Cloud
CVE-2025-55267Same product: Hcltech Aftermarket Cloud
CVE-2025-55263Same product: Hcltech Aftermarket Cloud

Affected Assets

hcltech
aftermarket cloud
1.0.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References