MEDIUM
CVE-2025-62340
CVSS
5.3
Description
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
Summary dbcve.org
HCL iControl has an inadequate session timeout vulnerability where user sessions remain active beyond acceptable periods of inactivity. This could allow attackers who gain access to valid session identifiers to hijack active user sessions or reuse stale sessions for unauthorized access.
Mitigation
Configure appropriate session timeout values in the HCL iControl web application settings to ensure sessions are automatically terminated after a defined period of inactivity.
Weakness (CWE)
CWE-613
EPSS Score
0.2%
Probability of exploitation in next 30 days
10.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.