CVE-2025-31953 Details
Description
HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties.
A vulnerability exists in HCL iAutomate version 6.5.1 due to hardcoded credentials, which could lead to unauthorized access or interception of confidential data. This issue poses a risk of data exposure if the credentials are accessed by unauthorized parties.
Users can upgrade to HCL iAutomate version 6.5.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL iAutomate support team.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0122646 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hcltech dryice iautomate | 6.5.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 10, 2025 | Reanalysis | [email protected] |
| Oct 9, 2025 | Initial Analysis | [email protected] |
| Jul 24, 2025 | New CVE Received | [email protected] |