Description
HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.
Published: 2026-07-21
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is the Lucky13 TLS padding oracle flaw, allowing an attacker to decrypt TLS traffic by manipulating padding bytes during the handshake. This constitutes a confidentiality breach and is categorized as a weak cryptographic algorithm issue (CWE-327).

Affected Systems

The affected product is HCLSoftware MyCloud. Specific affected versions are not listed in the available data. Administrators should review their MyCloud deployments for potential exposure.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network, with an attacker intercepting TLS sessions and performing a padding oracle attack to recover plaintext data.

Generated by OpenCVE AI on July 30, 2026 at 16:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available HCL MyCloud patch that addresses Lucky13 or upgrade to a version where the vulnerability is fixed.
  • Configure the MyCloud TLS settings to disable weak cipher suites and block CBC mode, ensuring only strong, authenticated cipher suites are used.
  • Monitor oracle activity, such as repeated try‑and‑fail padding errors, and investigate any anomalous patterns promptly.

Generated by OpenCVE AI on July 30, 2026 at 16:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware mycloud
Vendors & Products Hclsoftware
Hclsoftware mycloud

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.
Title HCL MyCloud was affected with SSL/TLS Protocol Affected with LUCKY13 Vulnerability.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hclsoftware Mycloud
Hcltech Dryice Mycloud
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-22T18:26:23.193Z

Reserved: 2026-06-22T13:39:47.965Z

Link: CVE-2026-56582

cve-icon Vulnrichment

Updated: 2026-07-22T18:13:48.477Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T18:17:02.170

Modified: 2026-08-03T14:40:08.783

Link: CVE-2026-56582

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T17:00:07Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm