Impact
The vulnerability is a Sensitive Data Exposure flaw in HCL iControl that allows attackers to download internal configuration files because the web server or application does not properly harden paths. This can reveal credentials, network addresses, or other sensitive data that may be used to compromise the system. The weakness is identified as CWE-497.
Affected Systems
The affected product is HCL iControl from HCL Software. No specific version numbers are listed; the vulnerability applies to any deployments that have the misconfigured web server or application settings that expose configuration files.
Risk and Exploitability
The CVSS score of 4 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector is via a web request that accesses an exposed configuration file; the attacker does not need authentication but must be able to reach the files. If the files contain credentials or system details, the impact could be confidentiality loss and potential subsequent lateral movement.
OpenCVE Enrichment