CVE-2026-66248
3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | iControl | v4.5.0 | affected |
Weaknesses
- CWE-209: CWE-209 Generation of error message containing sensitive information
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.