Description
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
Published: 2026-07-17
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The HCL Aftermarket EPC application is vulnerable to the Lucky 13 timing side‑channel attack. This flaw allows an attacker to manipulate the integrity of TLS and DTLS records, potentially enabling the interception or alteration of encrypted data. The weakness is classified as CWE‑425, which describes a failure to mitigate the impact of a timing side‑channel.

Affected Systems

All HCL Aftermarket EPC deployments that use TLS 1.1, TLS 1.2, DTLS 1.0 or 1.2, and legacy SSL 3.0 or TLS 1.0 are potentially affected. The CVE does not specify patch version numbers, but any installation of the product that relies on these protocols remains at risk until a fix is applied.

Risk and Exploitability

The CVSS score of 3.7 places this vulnerability in the low‑severity range, and the EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is a network‑based man‑in‑the‑middle that can observe and replay TLS handshakes to exploit the timing side‑channel; this inference is drawn from the description of the Lucky 13 flaw and the affected protocols.

Generated by OpenCVE AI on July 31, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HCL Aftermarket EPC to the latest release that incorporates the Lucky 13 fix.
  • Disable SSL 3.0, TLS 1.0, and TLS 1.1 on all affected servers and enforce use of TLS 1.2 or higher. If DTLS is required, ensure the implementation uses a patched version or is disabled.
  • Enable network intrusion detection to flag abnormal TLS handshake timing or repeated “Finished” message patterns that may indicate a Lucky 13 attempt.

Generated by OpenCVE AI on July 31, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Lucky 13 Timing Side-Channel Vulnerability in HCL Aftermarket EPC

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Lucky 13 Timing Side-Channel Vulnerability in HCL Aftermarket EPC

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Lucky 13 Vulnerability in HCL Aftermarket EPC Enabling TLS/DTLS Man-in-the-Middle Attacks

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Wed, 22 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Lucky 13 Vulnerability in HCL Aftermarket EPC Enabling TLS/DTLS Man-in-the-Middle Attacks

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:17:56.645Z

Reserved: 2024-01-18T07:29:59.076Z

Link: CVE-2024-23573

cve-icon Vulnrichment

Updated: 2026-07-17T15:17:52.230Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')