CVE-2024-12627

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 11, 2025
CWE ID 502

Summary

CVE-2024-42174 is a newly disclosed vulnerability affecting HCL MyXalytics. This issue permits username enumeration, enabling attackers to generate a list of valid usernames through targeted probing. This vulnerability could potentially be exploited to gain valuable information for further attacks or to launch brute-force or password guessing attacks against affected accounts. It is essential for HCL to release a patch as soon as possible to mitigate this risk. Users are advised to enable multi-factor authentication and monitor their accounts closely to prevent potential unauthorized access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share