Impact
The vulnerability is a broken access control flaw that permits an attacker to bypass authentication checks or exploit insecure direct object references, enabling privilege escalation and the unauthorized alteration or deletion of sensitive application data. This flaw is classified as CWE‑250 and would allow an adversary to gain higher access levels within the iControl system, potentially compromising data integrity and availability. The impact is that attackers can modify configuration, delete records, and undermine the security posture of the application without the need for initial credentials.
Affected Systems
Both the HCL Software iControl product and any deployments using the affected code are impacted. The CVE lists HCL Software iControl as the vendor/product combination, and version details are not disclosed, meaning all installations prior to the fix are potentially vulnerable. No specific patch version is provided in the data, so administrators should verify against the vendor's security advisory for the applicable release.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, while the EPSS score is not available, suggesting limited public data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote over the network, exploiting the web interface or API of iControl. An attacker with network access could send unauthenticated or poorly authenticated requests to manipulate protected resources, provided the missing checks are not mitigated.
OpenCVE Enrichment