Automation Bypass Vulnerability in HCL AION Software
CVE-2025-62314

5.6MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2025-62314?

HCL AION contains a vulnerability that permits the submission of automated or scripted requests to certain endpoints without adequate anti-automation controls. This lack of sufficient rate limiting and challenge mechanisms could lead to unintended behavior or create security risks under specific circumstances. It is crucial for users to implement appropriate safeguards to mitigate the potential impact of this vulnerability.

Affected Version(s)

AION v2.1.0

References

CVSS V3.1

Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.