Executive brief
HCL Aftermarket EPC, a platform for managing electronic parts catalogs, contains a flaw in its password reset system. An attacker can repeatedly trigger password reset requests to flood an email address or the system's mail server with messages. This can lead to a denial of service, disrupting normal business operations and preventing legitimate users from receiving important communications.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to improper control of interaction frequency (CWE-799) within its password recovery component. The application fails to implement a mail limitation mechanism, allowing an unauthenticated remote attacker to programmatically trigger an unlimited number of 'Forgot Password' emails. This can be exploited to perform email flooding attacks, potentially leading to a denial of service (DoS) of the mail server or the application's notification logic. The vulnerability is accessible over the network without user interaction.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: Initial advisory published by HCL Software and NVD.