Impact
The vulnerability in HCLMyCloud allows an attacker to initiate multiple concurrent sessions for a single user. This concurrent login flaw is a weakness in authentication enforcement (CWE‑613) and could lead to unauthorized access, session hijacking, or misuse of the account. Based on the description, it is inferred that an attacker must possess valid credentials to create a concurrent session.
Affected Systems
The affected product is HCLSoftware MyCloud. No specific version information is supplied, so all deployments of this product should be evaluated for potential exposure.
Risk and Exploitability
The CVSS base score of 3.1 indicates low severity, and the EPSS score of less than 1% implies a very low likelihood of exploitation. The weakness is not listed in the CISA KEV catalog. Attack scenarios likely require an authenticated session; a legitimate user or attacker with valid credentials could create a second concurrent session, undermining session safety and potentially allowing unauthorized actions.
OpenCVE Enrichment