Impact
HCL Hive lacks a rate‑limit on authentication attempts, which creates a condition where an attacker can repeatedly try login credentials at an unconstrained pace. The missing protective mechanism enables brute‑force or credential‑stuffing attacks, allowing an attacker to obtain legitimate user access if passwords are weak or reused. Additionally, a sustained flood of login attempts can exhaust server resources, producing a denial‑of‑service condition for legitimate users.
Affected Systems
The vulnerability affects HCLSoftware’s HCL Hive product. No specific version range is provided; the vendor advisory applies to any current release that has not yet implemented a rate‑limit. Organizations should consult the vendor’s support portal for relevant firmware or software updates.
Risk and Exploitability
The CVSS score of 5.3 places the flaw in the medium severity band, indicating that exploitation can compromise confidentiality or availability in a moderate‑risk environment. With no EPSS data available, the likelihood of timely exploitation is uncertain, but the lack of rate limiting logically makes brute‑force attacks easier. The flaw is not listed in the CISA KEV catalog, suggesting that no public exploits are known, yet the potential impact warrants prompt remediation. Based on the description, it is inferred that the most probable attack vector is the exposed authentication endpoint over HTTP or HTTPS, where an attacker can submit repeated credential attempts.
OpenCVE Enrichment