Impact
HCL MyCloud implements a weak password policy that allows user accounts to be protected by passwords that lack requisite complexity, length, or expiration requirements. This weakness increases the likelihood that legitimate usernames and weak passwords can be discovered or guessed, enabling an attacker to gain unauthorized access. The vulnerability is specifically a weakness in password enforcement rather than a flaw that directly allows remote code execution or denial of service.
Affected Systems
The affected product is HCL Software MyCloud; no specific version information is provided, so version details are unavailable.
Risk and Exploitability
The CVSS score of 3.1 indicates low overall severity, and the EPSS score of less than 1% signifies a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is brute‑force or credential‑based login attempts against the MyCloud authentication interface. No advanced privileges or remote code execution are required; exploitation simply results in unauthorized account access if the attacker guesses or enumerates a valid weak password. The impact is confined to user account integrity and potential access to any resources those accounts control.
OpenCVE Enrichment