CVE-2025-62312

LOW

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse, especially if not combined with secure transmission practices.

Scores

CVSS v3 3.0
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-522
Status published
Products (1)
HCL/AION 2.1.0
Published May 14, 2026
Tracked Since May 14, 2026