Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 24 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Email Flooding via Forget Password in HCL Aftermarket EPC Causes Denial of Service |
Thu, 23 Jul 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hclsoftware
Hclsoftware aftermarket Epc |
|
| Vendors & Products |
Hclsoftware
Hclsoftware aftermarket Epc |
Fri, 17 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences. | |
| Weaknesses | CWE-799 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-07-17T15:15:03.298Z
Reserved: 2024-01-18T07:29:56.729Z
Link: CVE-2024-23565
Updated: 2026-07-17T15:14:42.454Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T06:00:04Z