Description
HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The application fails to enforce limits on the number of password reset emails sent. This oversight represents a CWE‑799 (Unrestricted I/O) flaw, allowing an attacker to trigger an unlimited number of reset requests, each sending an email. The uncontrolled email traffic can exhaust the mail server’s resources, leading to denial of service or affecting other application logic.

Affected Systems

The vulnerability resides in HCL Software’s Aftermarket EPC system. No specific product version information was supplied, so any installation of the documented product could be susceptible.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to use the web interface’s Forget Password feature to trigger the flooding; a human attacker or an automated bot could launch the flood. The main outcome is service disruption or erosion of system reliability.

Generated by OpenCVE AI on July 31, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest HCL Aftermarket EPC patch or update that addresses the password‑reset email flooding issue
  • Configure the application or front‑end to enforce a rate limit or throttle on password‑reset requests
  • Monitor outgoing email traffic for abnormal volume and set mail‑server limits or thresholds to prevent resource exhaustion

Generated by OpenCVE AI on July 31, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Email Flooding via Unrestricted Forget Password Requests

Wed, 29 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Email Flooding via Forget Password in HCL Aftermarket EPC Causes Denial of Service

Fri, 24 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Email Flooding via Forget Password in HCL Aftermarket EPC Causes Denial of Service

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.
Weaknesses CWE-799
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:15:03.298Z

Reserved: 2024-01-18T07:29:56.729Z

Link: CVE-2024-23565

cve-icon Vulnrichment

Updated: 2026-07-17T15:14:42.454Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-799

    Improper Control of Interaction Frequency