Impact
The vulnerability allows an unauthorized actor to observe a license key in a standard HTTP response from HCL MyCloud, exposing a secret credential. This disclosure could enable an attacker to potentially lead to unauthorized access to licensing or administrative functions. The weakness is a classic information disclosure issue (CWE‑200).
Affected Systems
HCLSoftware’s MyCloud platform is affected; no specific product version was listed in the advisory, so all deployments of MyCloud are potentially vulnerable until a mitigation is applied.
Risk and Exploitability
The CVSS base score of 3.1 indicates a low impact, and the EPSS value of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, and no public exploits have been reported. Attackers would need to be able to request the relevant HTTP endpoint and capture the response, which can be performed from any network that can reach the service. Given the low score and scarce evidence of exploitation, the risk is considered minimal but still warrants remediation.
OpenCVE Enrichment