CVE-2025-62340
published 2026-06-17CVE-2025-62340: HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to…
PriorityP426medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.20%
10.6th percentile
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hcl_software | icontrol | — | — |
| hcltech | icontrol | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvelistv5v3.13.1LOWCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
HCL iControl 4.2.0 session expiration (KB0131511)
vuldb·2026-06-27·CVSS 5.3
CVE-2025-62340 [MEDIUM] HCL iControl 4.2.0 session expiration (KB0131511)
A vulnerability was found in HCL iControl 4.2.0. It has been classified as problematic. The affected element is an unknown function. This manipulation causes session expiration.
This vulnerability is handled as CVE-2025-62340. The attack can be initiated remotely. There is not any exploit available.
CVEList
HCL iControl was affected by Inadequate Session Timeout vulnerability
cvelistv5·2026-06-17·CVSS 3.1
CVE-2025-62340 [LOW] CWE-613 HCL iControl was affected by Inadequate Session Timeout vulnerability
HCL iControl was affected by Inadequate Session Timeout vulnerability
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
GHSA
HCL iControl was affected by Inadequate Session Timeout vulnerability.
ghsa_unreviewed·2026-06-17
CVE-2025-62340 [LOW] CWE-613 HCL iControl was affected by Inadequate Session Timeout vulnerability.
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-17
Published