Impact
The HCL Aftermarket EPC application is vulnerable to the Lucky 13 timing side‑channel attack. This flaw allows an attacker to manipulate the integrity of TLS and DTLS records, potentially enabling the interception or alteration of encrypted data. The weakness is classified as CWE‑425, which describes a failure to mitigate the impact of a timing side‑channel.
Affected Systems
All HCL Aftermarket EPC deployments that use TLS 1.1, TLS 1.2, DTLS 1.0 or 1.2, and legacy SSL 3.0 or TLS 1.0 are potentially affected. The CVE does not specify patch version numbers, but any installation of the product that relies on these protocols remains at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 3.7 places this vulnerability in the low‑severity range, and the EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The likely attack vector is a network‑based man‑in‑the‑middle that can observe and replay TLS handshakes to exploit the timing side‑channel; this inference is drawn from the description of the Lucky 13 flaw and the affected protocols.
OpenCVE Enrichment