Impact
The application fails to enforce limits on the number of password reset emails sent. This oversight represents a CWE‑799 (Unrestricted I/O) flaw, allowing an attacker to trigger an unlimited number of reset requests, each sending an email. The uncontrolled email traffic can exhaust the mail server’s resources, leading to denial of service or affecting other application logic.
Affected Systems
The vulnerability resides in HCL Software’s Aftermarket EPC system. No specific product version information was supplied, so any installation of the documented product could be susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to use the web interface’s Forget Password feature to trigger the flooding; a human attacker or an automated bot could launch the flood. The main outcome is service disruption or erosion of system reliability.
OpenCVE Enrichment