CVE-2024-23565

Summary

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareAftermarket EPCversion 1.0.0affected

Weaknesses

  • CWE-799: CWE-799: Improper Control of Interaction Frequency

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References