CVE-2025-31952
HCL iAutomate is affected by an insufficient session expiration
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.1EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jul 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L
Affected products
HCL Software · iAutomateWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →