Junglewise Threat Intelligence

CVE-2025-62312: HCL AION insufficiently protected credentials in authentication mechanism

CVE-2025-62312 · Severity: low · CVSS 3 · Published 2026-05-14

Technologies: HCL AION. Vendors: HCL.

Executive brief

HCL AION is an enterprise software platform that is currently affected by a security weakness in how it handles user logins. The system uses a basic authentication method that can allow an attacker on the same local network to intercept and steal user credentials. If exploited, this could lead to unauthorized access to the platform and the sensitive business data it manages.

Technical details

HCL AION utilizes an insecure authentication mechanism (CWE-522) by relying on basic authorization tokens. This implementation is susceptible to credential interception, particularly if the communication channel is not sufficiently encrypted or if an attacker is positioned on the adjacent network. According to the CVSS vector, the attack requires low privileges and user interaction from a target on the same local network. An attacker successfully exploiting this flaw could gain access to user credentials, leading to a loss of confidentiality. Users are advised to refer to HCL's official security bulletin for remediation steps.

Affected products

  • HCL AION

Timeline

  • 2026-05-14: disclosed: Initial disclosure by HCL Software
  • 2026-05-14: advisory: NVD publication date

References

Related threats