CVE-2025-62340: HCL iControl was affected by Inadequate Session Timeout vulnerability
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure HCL iControl to automatically terminate user sessions after a defined period of inactivity. Set an appropriate inactivity timeout according to your organization's policy and ensure idle sessions are invalidated (cookies/session tokens cleared) when the timeout is reached.
HCL iControl session_timeout = enable automatic termination after a period of inactivity (set per organizational policy)
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62340?
CVE-2025-62340 has a low severity rating of 3.1.
What software is affected by CVE-2025-62340?
CVE-2025-62340 affects HCL iControl.
What is the main issue with CVE-2025-62340?
CVE-2025-62340 involves an inadequate session timeout that fails to terminate user sessions after inactivity.
How can I mitigate CVE-2025-62340?
Mitigation for CVE-2025-62340 can involve implementing automatic session termination after a specified period of inactivity.
When was CVE-2025-62340 published?
CVE-2025-62340 was published on June 17, 2026.