VulnerabilityAnalyzed
CVE-2025-52648
HCL AION is affected by a vulnerability where offering images are not digitally signed.
CRITICAL 9.8EPSS 0.12%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-347
- Affected
- hcl/aion
- Source
- psirt@hcl.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.