---
id: CVE-2025-62347
title: HCL iControl was affected by Improper Input Validation vulnerability
summary: >-
  HCL iControl was affected by Improper Input Validation vulnerability. It is
  vulnerable to unexpected system behavior and potential security bypasses. This
  was caused by an implementation flaw in an architectural security tactic that
  fail…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-20
published: '2026-07-31'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T14:10:00.117'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62347'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0132395
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.0031
epssPercentile: 0.21394
ingestedAt: '2026-09-29T14:36:14.071Z'
---

## Overview

HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
