Impact
The vulnerability in HCL MyCloud arises from a missing cookie attribute path, allowing session cookies to be sent to unintended URLs or user agents. This flaw, classified as CWE‑614, can let an attacker read or modify session cookies, effectively hijacking user sessions and gaining unauthorized access to accounts.
Affected Systems
The affected system is HCL MyCloud, a product of HCLSoftware. No specific version information is supplied, meaning all releases prior to a confirmed patch should be considered vulnerable.
Risk and Exploitability
The CVSS score of 2.6 denotes low overall severity, and the EPSS of <1% indicates a very uncommon exploitation rate. The vulnerability is not included in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker setting a cookie with a broader path—such as through a phishing link or a compromised web resource—so that the session cookie is transmitted to more URLs. The exploitation prerequisites appear limited, making widespread automated attacks less probable.
OpenCVE Enrichment