CVE-2024-30150
Published: 25 February 2025
Description
HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.
Security Summary
CVE-2024-30150 is an improper access control vulnerability in HCL MyCloud, manifesting as an unauthenticated privilege escalation issue. This flaw allows unauthorized access that may result in information disclosure, as well as potential server-side request forgery (SSRF) and denial-of-service (DoS) attacks. The vulnerability is rated with a CVSS v3.1 base score of 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) and is associated with CWE-269 (Improper Privilege Management) and CWE-918 (Server-Side Request Forgery).
Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity and no user interaction required. Successful exploitation enables information disclosure of sensitive data and opens the door to SSRF for further internal network reconnaissance or abuse, along with potential DoS disruptions, all from external, privilege-less positions.
The HCL Software support advisory at https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119368 provides details on mitigation and patching instructions for affected HCL MyCloud deployments.
Details
- CWE(s)