# CVE-2025-52608

## Summary

- **CVE ID:** CVE-2025-52608
- **Severity:** LOW
- **CVSS Score:** 3.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **CWE:** CWE-614
- **Published:** Jun 4, 2026
- **Last Modified:** Jun 4, 2026

## Description

HCL  iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root.

## Affected Products

- HCL — iControl (4.0.0)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131061)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 0.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._