What is CVE-2026-56609?
A weak SSL/TLS version support vulnerability has been identified in HCL iControl, where the application uses outdated protocols like TLS 1.0 and 1.1. These lack modern security features and may lead to sensitive information exposure. It is recommended to configure the application to use TLS 1.2 or higher.
Azərbaycanca: HCL iControl tətbiqində zəif SSL/TLS versiyalarının (TLS 1.0, TLS 1.1) dəstəklənməsi aşkarlanıb. Bu protokollar köhnəlmiş təhlükəsizlik xüsusiyyətlərinə malikdir və məlumat ifşasına səbəb ola bilər. Tətbiqi TLS 1.2 və ya daha yuxarı versiyalardan istifadə edəcək şəkildə konfiqurasiya etmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: HCL
FAQ2
What is the main security risk of using TLS 1.0 and TLS 1.1 in HCL iControl?
Since these outdated protocols lack modern security features, they may lead to the exposure of sensitive information.
How can this vulnerability be mitigated?
By configuring the application to use TLS 1.2 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.