Impact
The vulnerability allows a malicious actor to perform brute‑force operations against the HCL Aftermarket EPC login interface, enabling them to guess or confirm the existence of valid user accounts. This capability is referred to as user enumeration, a weakness that can be exploited as a precursor to credential stuffing or further targeted attacks. The issue is classified under CWE‑204, indicating that the system does not adequately conceal authentication success or failure information.
Affected Systems
The affected product is HCLSoftware Aftermarket EPC. Specific version information was not disclosed in the available data, so administrators should verify the exact build of their installation against HCL’s security advisories.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity, suggesting that while the vulnerability alone does not lead to code execution or data disclosure, it does provide useful reconnaissance data to an attacker. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild at present, and the advisory does not list the flaw in the CISA KEV catalog. The most plausible attack vector is a network‑based brute‑force attempt from an external or internal attacker who can reach the EPC login service. Successful exploitation would allow the attacker to enumerate valid usernames, potentially facilitating subsequent credential‑guessing or phishing campaigns.
OpenCVE Enrichment