Junglewise Threat Intelligence

CVE-2024-23574: HCL Aftermarket EPC user enumeration via response discrepancy

CVE-2024-23574 · Severity: medium · CVSS 5.3 · Published 2026-07-17

Technologies: HCL Software Aftermarket EPC. Vendors: HCL Software.

Executive brief

HCL Aftermarket EPC, a platform used for managing electronic parts catalogs, is susceptible to user enumeration. An unauthorized attacker can use automated techniques to identify valid usernames within the system. This information can be used as a starting point for more targeted attacks, such as password guessing or phishing, potentially leading to unauthorized account access.

Technical details

HCL Aftermarket EPC version 1.0.0 is vulnerable to an observable response discrepancy (CWE-204). This flaw allows a remote, unauthenticated attacker to use brute-force techniques to confirm the existence of valid usernames by analyzing differences in the application's responses. The vulnerability is exploitable over the network without user interaction. While it does not directly allow for data modification or service disruption, it facilitates reconnaissance for subsequent credential-based attacks. Users are advised to consult HCL Software advisory KB0132294 for remediation steps.

Affected products

  • HCL Software Aftermarket EPC 1.0.0

Timeline

  • 2026-07-17: advisory: HCL Software published the security bulletin KB0132294.
  • 2026-07-17: disclosed: CVE-2024-23574 was published to the NVD.

References

Related threats