Impact
HCL MyCloud includes an IIS Server component that suffers from a known vulnerability, corresponding to CWE‑1104, and may expose the system to publicly disclosed weaknesses. Failure to exclude or remediate these weaknesses can allow an attacker to compromise the server, affecting confidentiality, integrity, or availability of the platform.
Affected Systems
HCL Software MyCloud installations are affected; specific versions are not listed in the available data.
Risk and Exploitability
The CVSS score of 2.2 indicates a low overall severity, and the EPSS score of less than 1% suggests a very low likelihood of immediate exploitation. The vulnerability is not listed in on the nature of the IIS Server component, the likely attack vector is remote and requires publicly reachable web services. The exploitation would depend on the presence of known IIS weaknesses and does not appear to have been leveraged in the wild or in documented attacks at the time of this report.
OpenCVE Enrichment