Impact
The vulnerability is a session timeout flaw that allows an attacker to hijack an unattended or abandoned active session. Because the application does not authenticate the session properly (CWE-613), the attacker gains the victim’s privileges and can perform any actions the victim could. The impact is direct unauthorized access to the application’s functions and data.
Affected Systems
HCL Software’s iControl application is affected. No specific version information is provided in the available data. The referenced HCL support article contains the vendor’s guidance for this issue.
Risk and Exploitability
The CVSS score is 3.1, indicating low severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, implying limited or no publicly known exploitation. The likely attack vector involves an adversary that has access to an already active session, such as through browser or network traffic. The risk is moderate for environments where session persistence or remote access is enabled, but the low severity suggests that the exploitation likelihood is low without such conditions.
OpenCVE Enrichment