Impact
The vulnerability stems from a misconfiguration in HCL iControl v4.3.0 that permits publicly accessible internal configuration files. An attacker able to request these files can gain insight into system internals, potentially including credentials, network topology, and other sensitive settings. The impact is primarily a breach of confidentiality, with no direct evidence of code execution or denial of service.
Affected Systems
HCL Software’s HCL iControl, specifically version 4.3.0, is affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate risk, while the EPSS score of <1% reflects a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, and no exploit has been reported. Likely exploitation would involve a remote attacker issuing HTTP requests to the web server, but no critical privileges or credentials are required beyond network access to the exposed endpoint.
OpenCVE Enrichment