HCL iControl是印度HCL公司的一个IT基础设施监控与自动化运维平台。 HCL iControl 4.3.0版本和4.4.0版本存在信任管理问题漏洞,该漏洞源于自动完成功能启用问题,可能导致在共享环境下攻击者通过浏览器建议枚举有效用户名、登录邮箱地址和账户标识符等敏感信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | HCL iControl | 4.3.0 and 4.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| HCL Software | HCL iControl | 4.3.0 and 4.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56567 | 5.1 MEDIUM | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-56569 | 4.0 MEDIUM | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-56568 | 3.7 LOW | HCL iControl is affected by multiple security vulnerabilities. |
| CVE-2026-56571 | 3.7 LOW | HCL iControl is affected by multiple security vulnerabilities. |
No comments yet