Impact
Based on the description, it is inferred that attackers could perform man‑in‑the‑middle operations, eavesdrop on or tamper with data in transit, and expose sensitive information that should be encrypted. HCL iControl currently accepts TLS 1.0 and TLS 1.1, both of which lack modern security features and are susceptible to numerous known attacks. This directly compromises the confidentiality and integrity of communications with the system.
Affected Systems
HCL Software’s HCL iControl is affected. No specific product versions are listed, so any deployment utilizing the software is potentially vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability is network‑based and could be exploited against any client–server session that negotiates TLS 1.0 or 1.1. The CVSS score of 4.8 indicates moderate risk; the lack of an EPSS score and absence from CISA’s KEV catalog suggest the exploit is not widely known or actively leveraged today. System owners should consider the potential for data exposure when using these legacy protocols and address the issue promptly.
OpenCVE Enrichment