SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-23577

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

HCL Aftermarket EPC is vulnerable due to inadequate validation of the HOST header, allowing arbitrary hosts to be accepted in HTTP requests. This weakness can lead to host header poisoning and potential server misconfigurations, posing security risks to the application. Organizations using HCL Aftermarket EPC should prioritize addressing this vulnerability to mitigate potential exploitation.

CVE
CVE-2024-23577
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%

Original NVD Description

HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.