Impact
The vulnerability lies in a missing Strict‑Transport‑Security (S‑TLS) policy, allowing attackers to strip SSL or perform man‑in‑the‑middle attacks and compromise secure communications. The weakness is identified as CWE‑523, a failure to enforce mandatory HTTPS . Without the HSTS header, an attacker can downgrade connections to HTTP, intercept traffic, and potentially inject malicious content.
Affected Systems
Affected product: HCLSoftware IntelliOps Event Management (IEM). No specific version range is supplied in the advisory, so all deployed instances of IEM without a recent HSTS implementation should be considered vulnerable.
Risk and Exploitability
The CVSS score of 3.7 places the vulnerability in a low‑to‑moderate severity range, and the EPSS score of less than 1% indicates that active exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via a network or web attack that exploits the lack of HSTS headers to force a downgrade of secure connections, enabling passive or active interception of traffic.
OpenCVE Enrichment