HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 | Vendor Advisory |
Configurations
History
27 Mar 2026, 17:25
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hcl aion
Hcl |
|
| Summary |
|
|
| CPE | cpe:2.3:a:hcl:aion:*:*:*:*:*:*:*:* | |
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0129410 - Vendor Advisory |
16 Mar 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-347 |
16 Mar 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:17
Updated : 2026-03-27 17:25
NVD link : CVE-2025-52648
Mitre link : CVE-2025-52648
CVE.ORG link : CVE-2025-52648
JSON object : View
Products Affected
hcl
- aion
CWE
CWE-347
Improper Verification of Cryptographic Signature
