ZeroHour

CVE-2024-42172

CVSS 3.1
9.8 critical
EPSS
<1%p33
Published
()
Modified
Description

HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.

Vendors
hcltech
Products
dryice myxalytics
Weakness
CWE-287, CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.