V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2025-55269
CVE
Critical

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use b…

CVSS
9.8
Critical
EPSS
0.00
p6
Published
2025-01-01
Updated
2025-01-01
Description

HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak passwords or use brute-force techniques to gain unauthorized access to user accounts.

Tags · CWE
Pre-auth
CWE-521
CAPEC-16
CAPEC-49
CAPEC-55
CAPEC-70
CAPEC-112
CAPEC-509
CAPEC-555
CAPEC-561
CAPEC-565
Affected products
Aftermarket_cloud
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p6
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-521
└ via CAPEC-561 · CWE-521
└ via CAPEC-70 · CWE-521
└ via CAPEC-112 · CWE-521
└ via CAPEC-49 · CWE-521
└ via CAPEC-55 · CWE-521
└ via CAPEC-565 · CWE-521
└ via CAPEC-555 · CWE-521
└ via CAPEC-555 · CWE-521
└ via CAPEC-509 · CWE-521
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
aftermarket_cloud*Tracked