CVE-2025-52644
Received Received - Intake
Insufficient Auditing in HCL AION Impairs Activity Traceability

Publication date: 2026-03-16

Last updated on: 2026-04-28

Assigner: HCL Software

Description
HCL AION is affected by a vulnerability where certain user actions are not adequately audited or logged. The absence of proper auditing mechanisms may reduce traceability of user activities and could potentially impact monitoring, accountability, or incident investigation processes.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-16
Last Modified
2026-04-28
Generated
2026-06-16
AI Q&A
2026-03-16
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
hcltech aion From 2.0.0 (inc) to 2.1.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-778 When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability in HCL AION involves inadequate auditing or logging of certain user actions. Because these actions are not properly recorded, it reduces the ability to trace user activities effectively.

Impact Analysis

The lack of proper auditing mechanisms can impact monitoring and accountability, making it harder to investigate incidents or understand user behavior. This could lead to delayed detection of malicious activities or unauthorized actions.

Compliance Impact

Inadequate auditing and logging can negatively affect compliance with standards and regulations such as GDPR and HIPAA, which often require detailed record-keeping and traceability of user actions to ensure accountability and support incident investigations.

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-52644. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart