VulnerabilityDeferred
CVE-2024-23566
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented.
MEDIUM 6.5EPSS 0.27%
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-804
- Source
- psirt@hcl.com
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.