Impact
The vulnerability is a missing access control flaw that allows users to access or invoke administrator‑level functions that they are not entitled to. Without appropriate authorization checks, legitimate users can view or modify privileged configuration settings, potentially compromising system integrity and confidentiality.
Affected Systems
The flaw affects HCL iControl from HCL Software. The advisory does not list specific version ranges, so any deployed installation may be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 3.7 classifies the weakness as low severity, and the EPSS score of 0.00162 indicates a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers who can authenticate with a normal user account are likely able to exploit this flaw through the web interface, enabling unauthorized administrative actions. Because the exploitation can be performed with existing credentials, the risk to organizations increases if privileged functions are accessed without proper role checks.
OpenCVE Enrichment