---
id: CVE-2024-23573
title: >-
  HCL Aftermarket EPC is vulnerable to attack since the Application is
  vulnerable to Lucky 13
summary: >-
  HCL Aftermarket EPC is vulnerable to attack since the Application is
  vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the
  TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous
  versions such as SSL…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-425
published: '2026-07-17'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T00:10:00.180'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-23573'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132294
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00244
epssPercentile: 0.14135
ingestedAt: '2026-10-02T01:05:54.730Z'
---

## Overview

HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
