CVE-2024-23574: Medium severity HCL Aftermarket EPC vulnerability
Published Jul 17, 2026
·Updated
HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system
Affected Software
1 affected component
HCL Aftermarket EPC
Event History
Jul 17, 2026
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-23574?
The severity of CVE-2024-23574 is medium, with a CVSS score of 5.3.
2
What type of attack is possible with CVE-2024-23574?
CVE-2024-23574 allows a malicious actor to use brute-force techniques to guess or confirm valid users in the HCL Aftermarket EPC system.
3
How can I mitigate the risks associated with CVE-2024-23574?
To mitigate the risks of CVE-2024-23574, implement account lockout policies and multi-factor authentication.
4
Is there a patch available for CVE-2024-23574?
As of now, there is no information regarding a patch specifically for CVE-2024-23574.
5
What software is affected by CVE-2024-23574?
CVE-2024-23574 affects HCL Aftermarket EPC software.