← back
CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration

CVSS 7.1 HIGHEPSS 0.3%CWE-613
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
24 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Affected products
HCL Software · iAutomate

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →