CVE-2025-52648
Awaiting Analysis
Awaiting Analysis - Queue
Unsigned Offering Images in HCL AION Allow Integrity Compromise
Publication date: 2026-03-16
Last updated on: 2026-03-27
Assigner: HCL Software
Description
Description
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcl | aion | From 2.0 (inc) to 2.1.2 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-347 | The product does not verify, or incorrectly verifies, the cryptographic signature for data. |