CVE-2025-62340: low-severity vulnerability in HCL Software iControl
HCL iControl was affected by Inadequate Session Timeout vulnerability
Published
8Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 3.1epss 0.2%
exploitation probability
0.2%top 91% of all CVEs
observed exploitation
nono source reports it
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected products
HCL Software · iControlRelated CVEs — HCL Software iControl
In the same product, most dangerous first.
CVE-2026-66246HIGHHCL iControl is affected by multiple security vulnerabilitiesEPSS 0.3%CVE-2026-66247MEDIUMCVE-2026-66247EPSS 0.2%CVE-2026-66248LOWHCL iControl is affected by an Improper Error Handling vulnerabilityEPSS 0.2%CVE-2026-66253LOWHCL iControl is affected by a Session Timeout vulnerabilityEPSS 0.1%CVE-2026-66249LOWHCL iControl is affected by a Missing Secure Attribute vulnerabilityEPSS 0.1%