CVE-2025-62313

MEDIUM

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced.

Title source: cna
STIX 2.1

Description

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

Scores

CVSS v3 5.4
EPSS 0.0018
EPSS Percentile 7.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-307
Status published
Products (1)
HCL/AION 2.1.0
Published May 14, 2026
Tracked Since May 14, 2026