Insecure HTTP Header Vulnerability in HCL AION
CVE-2025-52631
3.7LOW
What is CVE-2025-52631?
HCL AION is susceptible to a vulnerability due to a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header. This flaw can lead to insecure connections, increasing the potential for man-in-the-middle and protocol downgrade attacks. This issue is particularly impactful in version 2.0 of AION, as it compromises the integrity and confidentiality of data transmitted over the network.
Affected Version(s)
AION 2.0