Impact
The vulnerability, classified as Server Version Disclosure, allows an attacker to obtain the exact software version of a HCL MyCloud instance. The disclosed version can be used to determine other known weaknesses specific to that version. While the vulnerability itself does not provide direct code execution or unauthorized access, the information can lower the barriers to subsequent, more severe attacks. The weakness is identified as CWE‑200 and scored with a CVSS of 2.2, indicating a low severity but non‑negligible concern for systems exposed to external traffic.
Affected Systems
The affected product is HCL Software’s MyCloud platform. No specific version range is listed in the CNA data, so the risk applies generally to all MyCloud installations that reveal version information in server responses. Administrators should verify whether their deployment exposes version details in HTTP headers, error messages, or other publicly accessible areas.
Risk and Exploitability
Because the CVSS is low and the EPSS score is under 1%, the likelihood of this vulnerability being actively exploited today is minimal, and it is not part of the CISA KEV catalog. However, attackers can combine the disclosed version data with other publicly available exploits for that specific MyCloud release. The attack path is most likely a passive reconnaissance step that relies on the server’s exposed version header or default error pages. Mitigation focuses on eliminating the informational leak rather than patching a code flaw that would allow active compromise.
OpenCVE Enrichment