CVE-2025-52645 PUBLISHED

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification.

Assigner: HCL
Reserved: 18.06.2025 Published: 16.03.2026 Updated: 16.03.2026

HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 1.9

Product Status

Vendor HCL
Product AION
Versions Default: unaffected
  • Version 2.0 is affected

References