CVE-2025-52640
Received Received - Intake

Insufficient Access Separation in HCL AION Shared Storage

Vulnerability report for CVE-2025-52640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-13

Assigner: HCL Software

Description

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may be able to access or modify files beyond their intended scope, potentially resulting in unintended behavior or security impact under certain conditions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-13
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl aion *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL AION has a vulnerability due to shared storage lacking proper access separation. This allows processes using the same storage to access or modify files outside their intended scope, potentially causing unintended behavior or security issues under specific conditions.

Impact Analysis

This vulnerability could allow unauthorized access or modification of files, leading to data leaks, corruption, or system instability. Attackers with local access might exploit it to escalate privileges or disrupt operations.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized access or modification of sensitive data stored in shared storage. Unintended behavior due to improper access separation may lead to data breaches or integrity issues, which are critical concerns under these regulations.

Mitigation Strategies

Review and restrict access permissions to shared storage used by HCL AION components to ensure proper separation. Monitor file access logs for unauthorized modifications or access attempts. Consider isolating critical components to reduce shared storage exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-52640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart