Insecure HTTP Transmission in HCL AION Backend Services
CVE-2025-62311

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2025-62311?

HCL AION is susceptible to a vulnerability that allows backend service details to be transmitted over insecure HTTP channels. This situation can lead to the exposure of sensitive information to unauthorized parties, as data can be intercepted during transmission. It is crucial for users to ensure secure communication channels to protect their data effectively.

Affected Version(s)

AION 2.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.