Improper Access Control Vulnerability in HCL MyCloud
CVE-2024-30150

5.3MEDIUM

Key Information:

Vendor
HCL Software Software
Status
Mycloud
Vendor
CVE Published:
25 February 2025

Summary

HCL MyCloud is vulnerable to improper access control, allowing unauthenticated users to exploit the system. This vulnerability can facilitate unauthenticated privilege escalation, potentially leading to unauthorized access to sensitive information. Attackers may utilize this flaw to instigate Server-Side Request Forgery (SSRF) attacks or cause Denial of Service (DoS) disruptions, posing significant risks to the security and availability of the affected system.

Affected Version(s)

MyCloud 10.8.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.