CVE 3.7 LOW

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability._CVE-2025-52631

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L

Description

HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.

Basic Information

ID CVE-2025-52631
Source HCL
Published Feb 3, 2026 at 18:16
Modified Feb 3, 2026 at 19:12

Affected Product

Vendor HCL
Product AION
Version 2.0
Affected Versions HCL AION 2.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.