CVE-2025-62311

MEDIUM

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels.

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized access during transmission under certain conditions

Scores

CVSS v3 4.3
EPSS 0.0008
EPSS Percentile 0.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-319
Status published
Products (1)
HCL/AION 2.1.0
Published May 14, 2026
Tracked Since May 14, 2026