Impact
The vulnerability is the Lucky13 TLS padding oracle flaw, allowing an attacker to decrypt TLS traffic by manipulating padding bytes during the handshake. This constitutes a confidentiality breach and is categorized as a weak cryptographic algorithm issue (CWE-327).
Affected Systems
The affected product is HCLSoftware MyCloud. Specific affected versions are not listed in the available data. Administrators should review their MyCloud deployments for potential exposure.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote over the network, with an attacker intercepting TLS sessions and performing a padding oracle attack to recover plaintext data.
OpenCVE Enrichment