Junglewise Threat Intelligence

CVE-2024-23573: HCL Aftermarket EPC Lucky 13 timing attack in TLS/DTLS

CVE-2024-23573 · Severity: low · CVSS 3.7 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is susceptible to a known cryptographic timing attack. An attacker positioned between the user and the server could potentially decrypt small amounts of sensitive information from encrypted sessions. While the risk is rated as low due to the technical difficulty of the attack, it could lead to the exposure of private data.

Technical details

HCL Aftermarket EPC version 1.0.0 is vulnerable to the 'Lucky 13' timing attack (CWE-208). This vulnerability exists in the application's handling of TLS 1.1, TLS 1.2, DTLS 1.0, and DTLS 1.2, as well as legacy protocols like SSL 3.0 and TLS 1.0. The flaw stems from differences in processing time for different padding errors in CBC-mode ciphers. A network-based attacker performing a man-in-the-middle attack can use these timing differences as a side-channel to potentially decrypt sensitive information from the encrypted stream. The attack requires high complexity and a large number of samples to be successful.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: NVD published the CVE record based on HCL Software's disclosure.

References

Related threats