Executive brief
HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is susceptible to user enumeration. An unauthorized attacker can use automated techniques to identify valid usernames within the system. This information can be used as a starting point for more targeted attacks, such as password guessing or phishing, potentially leading to unauthorized account access.
Technical details
HCL Aftermarket EPC version 1.0.0 is vulnerable to an observable response discrepancy (CWE-204). This flaw allows a remote, unauthenticated attacker to use brute-force techniques to confirm the existence of valid usernames by analyzing differences in the application's responses. The vulnerability is exploitable over the network without user interaction. While it does not directly allow for data modification or service disruption, it facilitates reconnaissance for subsequent credential-based attacks. Users are advised to consult HCL Software advisory KB0132294 for remediation steps.
Affected products
- HCL Software Aftermarket EPC 1.0.0
Timeline
- 2026-07-17: advisory: HCL Software published the security bulletin KB0132294.
- 2026-07-17: disclosed: CVE-2024-23574 was published to the NVD.