MEDIUM

CVE-2025-62340

Hcltech Icontrol 2026-06-17 CVSS v3.1
CVSS
5.3

Description

HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity

Summary dbcve.org

HCL iControl has an inadequate session timeout vulnerability where user sessions remain active beyond acceptable periods of inactivity. This could allow attackers who gain access to valid session identifiers to hijack active user sessions or reuse stale sessions for unauthorized access.

Mitigation

Configure appropriate session timeout values in the HCL iControl web application settings to ensure sessions are automatically terminated after a defined period of inactivity.

Weakness (CWE)

CWE-613

EPSS Score

0.2%
Probability of exploitation in next 30 days
10.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE