Impact
The vulnerability arises from the absence of a captcha mechanism in HCL Aftermarket EPC, allowing attackers to submit repeated authentication requests. This enables brute‑force attacks against user accounts and can facilitate enumeration of valid usernames or account identifiers, thereby exposing credential information and potentially serving as a foothold for further compromise.
Affected Systems
The affected product is HCL Software Aftermarket EPC. No version details are supplied by the CNA, so all releases of this application are considered potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as moderate. The EPSS score of less than 1% indicates that extensive exploitation is currently unlikely, yet the weakness remains a real risk because it permits automated credential attempts and discovery of legitimate accounts. The vulnerability is not listed in the CISA KEV catalog, implying that there are no known public exploits. Based on the description, attackers would typically send repeated authentication requests from the internet to try many username/password combinations, and the absence of a verification step means such attempts can be performed at scale.
OpenCVE Enrichment