VYPR
Medium severity4.8NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026

CVE-2025-52648

CVE-2025-52648

Description

HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system

Affected products

3
  • HCL Software/AION3 versions
    cpe:2.3:a:hcl:aion:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:hcl:aion:*:*:*:*:*:*:*:*range: >=2.0,<2.1.2
    • (no CPE)
    • (no CPE)range: 2.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.