Impact
The vulnerability is an improper error handling flaw in HCL Software iControl that allows an unauthenticated attacker to trigger verbose database and system errors. These detailed error messages can reveal sensitive internal infrastructure information that an attacker might use to design more sophisticated, targeted attacks. The impact is limited to information disclosure and does not directly provide control over the system.
Affected Systems
This weakness affects the HCL Software iControl product. No specific affected versions are listed, so all deployed instances of iControl should be reviewed for potential exposure.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity level, and the EPSS score is not available, which suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access to the iControl service and the ability to invoke error conditions; no elevated privileges are required.
OpenCVE Enrichment