CVE-2025-52649
LOWHCL AION is affected by a vulnerability where certain identifiers may be predictable in nature
Title source: cnaDescription
HCL AION is affected by a vulnerability where certain identifiers may be predictable in nature. Predictable identifiers may allow an attacker to infer or guess system-generated values, potentially leading to limited information disclosure or unintended access under specific conditions.
Scores
CVSS v3
1.8
EPSS
0.0003
EPSS Percentile
7.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Details
CWE
CWE-200
Status
published
Products (2)
HCL/AION
2.0
hcltech/aion
< 2.1.2
Published
Mar 16, 2026
Tracked Since
Mar 16, 2026