CVE-2024-42172
—CVSS 3.1
9.8 critical
EPSS
<1%p33
Published
()
Modified
Description
HCL MyXalytics is affected by broken authentication. It allows attackers to compromise keys, passwords, and session tokens, potentially leading to identity theft and system control. This vulnerability arises from poor configuration, logic errors, or software bugs and can affect any application with access control, including databases, network infrastructure, and web applications.
- Vendors
- hcltech
- Products
- dryice myxalytics
- Weakness
- CWE-287, CWE-522
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.