HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.
History

Fri, 09 Jan 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dryice Mycloud
Weaknesses CWE-918
CPEs cpe:2.3:a:hcltech:dryice_mycloud:10.8.1:*:*:*:*:*:*:*
Vendors & Products Hcltech
Hcltech dryice Mycloud

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 22:30:00 +0000

Type Values Removed Values Added
Description HCL MyCloud is affected by Improper Access Control - an unauthenticated privilege escalation vulnerability which may lead to information disclosure and potential for Server-Side Request Forgery (SSRF) and Denial of Service(DOS) attacks from unauthenticated users.
Title An unauthenticated privilege escalation vulnerability affects HCL MyCloud
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-02-25T22:21:28.699Z

Updated: 2025-02-26T15:32:44.264Z

Reserved: 2024-03-22T23:57:26.413Z

Link: CVE-2024-30150

cve-icon Vulnrichment

Updated: 2025-02-26T14:50:25.270Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-25T23:15:10.753

Modified: 2026-01-09T02:42:02.167

Link: CVE-2024-30150

cve-icon Redhat

No data.