CVE-2025-52608: low-severity vulnerability in HCL iControl
HCL iControl was affected by Missing Cookie Attributes vulnerability.
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 0.1%
exploitation probability
0.1%top 99% of all CVEs
observed exploitation
nono source reports it
HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Affected products
HCL · iControlRelated CVEs — HCL iControl
In the same product, most dangerous first.
CVE-2025-52612HIGHHCL iControl was affected by Export CSV - CSV Injection vulnerability.EPSS 0.2%CVE-2025-52606MEDIUMHCL iControl was affected by Weak Input Validation vulnerability. .EPSS 0.2%CVE-2025-52609LOWHCL iControl was affected by Missing Security Headers vulnerability.EPSS 0.2%CVE-2025-52611LOWHCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerabilityEPSS 0.2%