Fiche vulnérabilité
CVE-2024-42173 : faille moyenne hcltech dryice myxalytics (CVSS 4.8)
Description
HCL MyXalytics is affected by an improper password policy implementation vulnerability. Weak passwords and lack of account lockout policies allow attackers to guess or brute-force passwords if the username is known.
En bref
- Sévérité
- Moyenne (CVSS 4.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
- Exploitation active
- Non signalée par la CISA
- Publication
- 11 janv. 2025
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- hcltech dryice myxalytics