Insecure Authentication in HCL AION by HCL Technologies
CVE-2025-62312

3LOW

Key Information:

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2025-62312?

HCL AION is prone to a vulnerability that utilizes basic authorization tokens for user authentication. This mechanism, if not paired with secure transmission practices, can expose user credentials, making them susceptible to interception or misuse. Organizations using HCL AION should implement stronger authentication measures and secure communication protocols to mitigate potential risks associated with this vulnerability.

Affected Version(s)

AION 2.1.0

References

CVSS V3.1

Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.