CVE-2025-55276
Internal IP Disclosure in HCL Aftermarket DPC Exposes Network Layout
Publication date: 2026-03-26
Last updated on: 2026-03-26
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | aftermarket_cloud | 1.0.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in HCL Aftermarket DPC is an Internal IP Disclosure issue. It allows attackers to gain information about the internal IP addresses within an organization's network, effectively giving them a clearer map of the network layout.
How can this vulnerability impact me? :
This vulnerability can impact you by exposing internal network information to attackers. Although it does not directly compromise confidentiality, integrity, or availability of data, it provides attackers with valuable information that could be used to plan further attacks or reconnaissance within the network.