CVE-2025-52648
Last modified
CVE-2025-52648 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hcl | Aion | >= 2.0, < 2.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-52648?
How severe is CVE-2025-52648?
How do I fix CVE-2025-52648?
Are you affected by CVE-2025-52648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
