Hcl Software Icontrol vulnerabilities
6 known vulnerabilities affecting hcl_software/icontrol.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW3
Vulnerabilities
Page 1 of 1
CVE-2026-66246P2HIGHCVSS 8.8vv4.5.02026-10-01
CVE-2026-66246 [HIGH] CWE-250 CVE-2026-66246: iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to expl
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
nvd
CVE-2025-62340P4MEDIUMCVSS 5.3vv4.2.02026-06-17
CVE-2025-62340 [MEDIUM] CWE-613 CVE-2025-62340: HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
cvelistv5nvd
CVE-2026-66247P4MEDIUMCVSS 4.3vv4.5.02026-10-01
CVE-2026-66247 [MEDIUM] CWE-942 CVE-2026-66247: iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
nvd
CVE-2026-66248P4LOWCVSS 3.1vv4.5.02026-10-01
CVE-2026-66248 [LOW] CWE-209 CVE-2026-66248: iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticat
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.
nvd
CVE-2026-66253P4LOWCVSS 3.1vv4.5.02026-10-01
CVE-2026-66253 [LOW] CWE-613 CVE-2026-66253: iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.
nvd
CVE-2026-66249P4LOWCVSS 3.1vv4.5.02026-10-01
CVE-2026-66249 [LOW] CWE-614 CVE-2026-66249: iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to i
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
nvd