Hcltech
Hcltech Icontrol: vulnerabilidades y CVE
Hcltech Icontrol tiene 15 vulnerabilidades publicadas, 15 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses15
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-66249 | Baja (3.1) | — | — | 1 oct 2026 | iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive… |
| CVE-2026-66246 | Alta (8.8) | — | — | 1 oct 2026 | iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the… |
| CVE-2026-56609 | Media (6.5) | 0.15% | — | 3 ago 2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features,… |
| CVE-2026-56608 | Media (5.3) | 0.27% | — | 3 ago 2026 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without… |
| CVE-2026-56571 | Media (5.3) | 0.29% | — | 31 jul 2026 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common… |
| CVE-2026-56570 | Media (5.3) | 0.30% | — | 31 jul 2026 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from… |
| CVE-2026-56569 | Baja (3.3) | 0.14% | — | 31 jul 2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. |
| CVE-2026-56568 | Media (5.3) | 0.33% | — | 31 jul 2026 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages… |
| CVE-2026-56567 | Baja (3.3) | 0.14% | — | 31 jul 2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. |
| CVE-2025-62340 | Media (5.3) | 0.20% | — | 17 jun 2026 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity |
| CVE-2025-52612 | Alta (8.8) | 0.20% | — | 4 jun 2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . |
| CVE-2025-52611 | Media (4.3) | 0.16% | — | 4 jun 2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code… |
| CVE-2025-52609 | Media (5.3) | 0.16% | — | 4 jun 2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. |
| CVE-2025-52608 | Media (4.3) | 0.10% | — | 4 jun 2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. |
| CVE-2025-52606 | Media (4.3) | 0.17% | — | 4 jun 2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.