Junglewise Threat Intelligence

CVE-2024-23565: HCL Aftermarket EPC email flooding in Forgot Password functionality

CVE-2024-23565 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform for managing electronic parts catalogs, contains a flaw in its password reset system. An attacker can repeatedly trigger password reset requests to flood an email address or the system's mail server with messages. This can lead to a denial of service, disrupting normal business operations and preventing legitimate users from receiving important communications.

Technical details

HCL Aftermarket EPC version 1.0.0 is vulnerable to improper control of interaction frequency (CWE-799) within its password recovery component. The application fails to implement a mail limitation mechanism, allowing an unauthenticated remote attacker to programmatically trigger an unlimited number of 'Forgot Password' emails. This can be exploited to perform email flooding attacks, potentially leading to a denial of service (DoS) of the mail server or the application's notification logic. The vulnerability is accessible over the network without user interaction.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: Initial advisory published by HCL Software and NVD.

References

Related threats