CVE-2024-23573
Estado: AplazadaBaja (3.7)—
HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 3.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.24%
- Percentil entre todas las CVEs puntuadas: 14
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-425
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-23573",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-23573",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-17T15:17:45.705792Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.7,
"attackVector": "NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "HCLSoftware",
"product": "Aftermarket EPC",
"versions": [
{
"status": "affected",
"version": "version 1.0.0"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-17T14:17:17.573",
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294",
"source": "psirt@hcl.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"description": [
{
"lang": "en",
"value": "CWE-425"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack."
},
{
"lang": "es",
"value": "HCL Aftermarket EPC es vulnerable a ataques ya que la Aplicación es vulnerable a Lucky 13. Eso hace posible el SS LLUCKY13 y afecta a las implementaciones de TLS 1.1 y 1.2 y DTLS 1.0 o 1.2. También afecta a versiones anteriores como SSL 3.0 y TLS 1.0. Esto también puede considerarse un tipo de ataque man-in-the-middle."
}
],
"lastModified": "2026-10-02T00:10:00.180",
"sourceIdentifier": "psirt@hcl.com"
}