CVE-2025-52631
Unknown Unknown - Not Provided
Missing or Insecure HSTS Header in HCL AION 2.0 Enables MITM Attacks

Publication date: 2026-02-03

Last updated on: 2026-04-27

Assigner: HCL Software

Description
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-02-03
Last Modified
2026-04-27
Generated
2026-06-16
AI Q&A
2026-02-04
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcltech aion 2.0.0
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in HCL AION is due to a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header. HSTS is a security feature that forces web browsers to only connect to a website using HTTPS, preventing insecure HTTP connections.

Because the HSTS header is missing or insecure, attackers can exploit this by forcing insecure connections, which may lead to man-in-the-middle attacks or protocol downgrade attacks.

Impact Analysis

This vulnerability can allow attackers to intercept or manipulate the communication between the user and the application by exploiting insecure connections.

  • Man-in-the-middle attacks where attackers can eavesdrop or alter data.
  • Protocol downgrade attacks that force the connection to use less secure protocols.

Overall, this can lead to exposure of sensitive information or reduced security of the application.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-52631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart