Lucene search

K
cveHCLCVE-2024-23557
HistoryApr 18, 2024 - 7:15 p.m.

CVE-2024-23557

2024-04-1819:15:09
CWE-200
HCL
web.nvd.nist.gov
32
hcl connections
user enumeration
vulnerability
brute force attack

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

HCL Connections contains a user enumeration vulnerability. Certain actions could allow an attacker to determine if the user is valid or not, leading to a possible brute force attack.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Connections",
    "vendor": "HCL Software",
    "versions": [
      {
        "status": "affected",
        "version": "7.0, 8.0"
      }
    ]
  }
]

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

9.0%

Related for CVE-2024-23557