CVE-2025-52608

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:icontrol:4.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-04 12:16

Updated : 2026-07-22 20:10


NVD link : CVE-2025-52608

Mitre link : CVE-2025-52608

CVE.ORG link : CVE-2025-52608


JSON object : View

Products Affected

hcltech

  • icontrol
CWE
CWE-614

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute