SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23565

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is susceptible to email flooding due to inadequate mail limitation controls in its "Forget Password" functionality. This vulnerability could allow an attacker, whether human or automated, to disrupt service availability, manipulate program logic, or trigger other negative impacts. Organizations using this application should prioritize addressing this issue to mitigate potential denial-of-service attacks.

CVE
CVE-2024-23565
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%

Original NVD Description

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.