Impact
A vulnerability in HCL AION allows generated containers to run binaries with root-level privileges, giving an attacker elevated permissions within the container. This can enable unauthorized access to sensitive data or further compromise the host system if the container escapes isolation. The issue is a privilege escalation flaw (CWE-345).
Affected Systems
HCL AION products are affected. All releases of the HCL AION platform that generate containers without proper privilege restrictions are vulnerable. Specific version details are not provided, so the risk applies to all supported installations until an update is applied.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, while the EPSS score of less than 1% shows a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the ability to influence or create containers, suggesting that a local or privileged attacker could exploit the flaw. Applying an official patch reduces the attack surface and eliminates the privilege escalation path.
OpenCVE Enrichment