ZeroHour

CVE-2025-31952

CVSS 3.1
7.1 high
EPSS
<1%p25
Published
()
Modified
Description

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.

Vendors
hcltech
Products
dryice iautomate
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L

In the news

No ingested article mentions this CVE yet.