Skip to content

Commit b7580d6

Browse files
Sync EUVD catalog: Sat Jul 18 00:35:16 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 6fab7ea commit b7580d6

338 files changed

Lines changed: 11197 additions & 87 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2019-20200",
3+
"enisaUuid": "b32f2ae4-051f-3a54-8f96-813654be6154",
4+
"description": "**UNSUPPORTED WHEN ASSIGNED**\u00a0 Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation.\n\nRefer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers\u00a0' section on the ASUS Security Advisory for more information.",
5+
"datePublished": "Jul 17, 2026, 6:00:10 AM",
6+
"dateUpdated": "Jul 17, 2026, 10:10:36 AM",
7+
"baseScore": 7.3,
8+
"baseScoreVersion": "4.0",
9+
"baseScoreVector": "CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
10+
"references": "https://www.asus.com/security-advisory\n",
11+
"aliases": "GHSA-6jpp-g7h2-ch5p\nCVE-2019-25764\n",
12+
"assigner": "ASUS",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "b318af7a-1346-34d3-8768-75f42bdf2523",
17+
"product": {
18+
"name": "AURA SYNC",
19+
"vendor": {
20+
"name": "ASUS"
21+
}
22+
},
23+
"product_version": "0 <1.07.84"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "cf38dc1e-806f-3c59-ac71-f38143137dc1",
29+
"vendor": {
30+
"name": "ASUS"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55658",
3+
"enisaUuid": "eb9fe055-e5e2-3fea-8231-36e478f4d2d2",
4+
"description": "HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.",
5+
"datePublished": "Jul 17, 2026, 1:25:40 PM",
6+
"dateUpdated": "Jul 17, 2026, 1:54:47 PM",
7+
"baseScore": 9.1,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131787\n",
11+
"aliases": "GHSA-wmr2-f2gc-hxq6\nCVE-2024-23564\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "6938ae33-a325-32ad-af27-11f18cfdbcff",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "943558ff-f57b-38e5-a2e6-ba6a952310aa",
29+
"vendor": {
30+
"name": "HCL Software"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55659",
3+
"enisaUuid": "8d85764c-6506-3304-8015-9a62053cdf24",
4+
"description": "HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.",
5+
"datePublished": "Jul 17, 2026, 1:28:43 PM",
6+
"dateUpdated": "Jul 17, 2026, 1:54:13 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "GHSA-5hrc-frp7-8xrq\nCVE-2024-23567\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "ef57377b-0785-3c48-b178-8679bb0cebc3",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "c7f55bbf-34f9-3099-909e-241cbfe5daa4",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55660",
3+
"enisaUuid": "1a557e5e-ac91-37ec-8510-503096b1be0b",
4+
"description": "HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn\u2019t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration",
5+
"datePublished": "Jul 17, 2026, 1:32:42 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:13:56 PM",
7+
"baseScore": 6.5,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "CVE-2024-23566\nGHSA-q228-9crw-3vg9\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "0d025ba1-b08c-3b51-9fd1-c46af0d7b58b",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "31afd94b-f9a6-313d-ae56-98ed7e370459",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55661",
3+
"enisaUuid": "45b85c14-a8c0-3690-afe2-fbb03cfd86ec",
4+
"description": "HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.",
5+
"datePublished": "Jul 17, 2026, 1:36:31 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:15:03 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "CVE-2024-23565\nGHSA-j7fc-22wg-4jh8\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "d27c2400-f944-3bcd-82f2-e0c00a2930db",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "f48a1c49-f4a6-3680-821d-f0a48d0c12c7",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55662",
3+
"enisaUuid": "7b1dfbf5-54ab-313c-9741-45eacaf20122",
4+
"description": "HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.",
5+
"datePublished": "Jul 17, 2026, 1:38:28 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:17:21 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "CVE-2024-23568\nGHSA-34jp-jwp8-9p5j\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "191c522e-5712-3c19-acca-fa9b9472a0f2",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "629f97d7-f0e6-386f-8edc-a821a3238530",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55663",
3+
"enisaUuid": "8d7523e2-3ef9-3868-865c-2b6186be4862",
4+
"description": "HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.",
5+
"datePublished": "Jul 17, 2026, 1:42:13 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:17:56 PM",
7+
"baseScore": 3.7,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "CVE-2024-23573\nGHSA-2hrh-mjr6-qj4v\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "86e65503-e000-3c0a-a5ef-b70c82e6e363",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "b57ee36b-d0ec-39da-a654-487e517b5df4",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55664",
3+
"enisaUuid": "9287aa9d-d589-3b4b-b2ad-c913e4c3bc86",
4+
"description": "HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.",
5+
"datePublished": "Jul 17, 2026, 1:42:48 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:18:44 PM",
7+
"baseScore": 4.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "GHSA-vx9w-v74f-37mq\nCVE-2024-23571\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "3c23a303-5bc3-3740-9e06-a5872152dedb",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "2487bd67-3006-3421-90fa-b9bc441d0236",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55665",
3+
"enisaUuid": "0c05a349-1fed-3c4b-8980-213bcae09293",
4+
"description": "HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.",
5+
"datePublished": "Jul 17, 2026, 1:43:25 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:19:29 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "GHSA-fc8r-r2v5-2w2v\nCVE-2024-23575\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "7bf7924c-c8f2-30a2-b63a-1b82bf70315d",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "1f0f3ac3-8a2c-3155-ad53-e8ae9031dda4",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
{
2+
"id": "EUVD-2024-55666",
3+
"enisaUuid": "58743640-41bf-3b3a-95f8-181c847031e3",
4+
"description": "HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.",
5+
"datePublished": "Jul 17, 2026, 1:45:04 PM",
6+
"dateUpdated": "Jul 17, 2026, 3:20:14 PM",
7+
"baseScore": 5.3,
8+
"baseScoreVersion": "3.1",
9+
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
10+
"references": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294\n",
11+
"aliases": "GHSA-3j9w-8rx6-5cw3\nCVE-2024-42214\n",
12+
"assigner": "HCL",
13+
"epss": 0.0,
14+
"enisaIdProduct": [
15+
{
16+
"id": "9b362b64-1123-3752-a87a-679dd766dc2d",
17+
"product": {
18+
"name": "Aftermarket EPC",
19+
"vendor": {
20+
"name": "HCL Software"
21+
}
22+
},
23+
"product_version": "version 1.0.0"
24+
}
25+
],
26+
"enisaIdVendor": [
27+
{
28+
"id": "af1fea07-e195-325e-b670-0270eb6134c3",
29+
"vendor": {
30+
"name": "HCLSoftware"
31+
}
32+
}
33+
]
34+
}

0 commit comments

Comments
 (0)