4.8
CVE-2024-42173
- EPSS 0.17%
- Veröffentlicht 11.01.2025 07:15:08
- Zuletzt bearbeitet 16.05.2025 13:47:55
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL MyXalytics is affected by an improper password policy implementation vulnerability
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Dryice Myxalytics Version6.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.379 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.8 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
|
| psirt@hcl.com | 4.8 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
|
CWE-521 Weak Password Requirements
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.