Executive brief
HCL AION is affected by a security flaw where certain data is transmitted or processed without encryption. This could allow an attacker on the same local network to intercept sensitive information or gain unauthorized access to data. Such an incident could lead to the exposure of internal business communications or operational data.
Technical details
HCL AION fails to enforce encryption for specific data transmissions or operations, a vulnerability classified as CWE-319 (Cleartext Transmission of Sensitive Information). The attack vector is restricted to the adjacent network (AV:A) and requires high complexity (AC:H) along with user interaction (UI:R). An attacker positioned on the same local network could potentially intercept unencrypted traffic to capture sensitive data or perform unauthorized operations. HCL has released a security bulletin (KB0130636) addressing this and other vulnerabilities in the AION product.
Affected products
- HCL AION
Timeline
- 2026-05-14: disclosed: Initial disclosure by HCL Software
- 2026-05-14: advisory: NVD publication date