Improper Access Control Vulnerability in HCL MyCloud
CVE-2024-30150
5.3MEDIUM
Key Information:
- Vendor
- HCL Software Software
- Status
- Mycloud
- Vendor
- CVE Published:
- 25 February 2025
Summary
HCL MyCloud is vulnerable to improper access control, allowing unauthenticated users to exploit the system. This vulnerability can facilitate unauthenticated privilege escalation, potentially leading to unauthorized access to sensitive information. Attackers may utilize this flaw to instigate Server-Side Request Forgery (SSRF) attacks or cause Denial of Service (DoS) disruptions, posing significant risks to the security and availability of the affected system.
Affected Version(s)
MyCloud 10.8.1
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved