Description
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Published: 2026-07-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a malicious actor to perform brute‑force operations against the HCL Aftermarket EPC login interface, enabling them to guess or confirm the existence of valid user accounts. This capability is referred to as user enumeration, a weakness that can be exploited as a precursor to credential stuffing or further targeted attacks. The issue is classified under CWE‑204, indicating that the system does not adequately conceal authentication success or failure information.

Affected Systems

The affected product is HCLSoftware Aftermarket EPC. Specific version information was not disclosed in the available data, so administrators should verify the exact build of their installation against HCL’s security advisories.

Risk and Exploitability

The CVSS score of 5.3 reflects a moderate severity, suggesting that while the vulnerability alone does not lead to code execution or data disclosure, it does provide useful reconnaissance data to an attacker. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild at present, and the advisory does not list the flaw in the CISA KEV catalog. The most plausible attack vector is a network‑based brute‑force attempt from an external or internal attacker who can reach the EPC login service. Successful exploitation would allow the attacker to enumerate valid usernames, potentially facilitating subsequent credential‑guessing or phishing campaigns.

Generated by OpenCVE AI on August 1, 2026 at 08:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check HCLSoftware’s official channels for an updated patch or the latest release of Aftermarket EPC that addresses the enumeration issue
  • Configure the system to enforce account lockout or rate limiting after a defined number of failed login attempts, to impede brute‑force attempts
  • Enable multi‑factor authentication for all user accounts to ensure that knowledge of a valid username does not equate to access
  • Deploy monitoring tools to detect and alert on repeated authentication failures or anomalous login activity

Generated by OpenCVE AI on August 1, 2026 at 08:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 08:45:00 +0000

Type Values Removed Values Added
Title Brute‑Force User Enumeration in HCL Aftermarket EPC

Wed, 29 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Brute‑Force User Enumeration in HCL Aftermarket EPC

Sun, 26 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title User Enumeration via Brute-Force in HCL Aftermarket EPC

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware aftermarket Epc
Vendors & Products Hclsoftware
Hclsoftware aftermarket Epc

Wed, 22 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title User Enumeration via Brute-Force in HCL Aftermarket EPC

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Description HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Weaknesses CWE-204
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Aftermarket Epc
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-17T15:20:50.789Z

Reserved: 2024-01-18T07:29:59.076Z

Link: CVE-2024-23574

cve-icon Vulnrichment

Updated: 2026-07-17T15:20:44.058Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:30:03Z

Weaknesses
  • CWE-204

    Observable Response Discrepancy