Impact
A vulnerability in HCL AION allows the use of basic authorization tokens for authentication, a scheme that exposes stored credentials to interception or misuse if not protected by secure transmission methods. The weakness is a lack of confidentiality controls associated with basic authentication, identified as CWE-522. This can lead to unauthorized access to application data if credentials are captured or spoofed.
Affected Systems
The affected product is HCL AION. No specific version information is provided in the available CNA data, so all installations using basic authentication mechanisms are potentially impacted.
Risk and Exploitability
The CVSS score of 3 indicates a low severity risk, and the EPSS score is not available, while the vulnerability is not listed in the CISA KEV catalog. Exploitation would most likely involve passive network monitoring or capturing traffic that carries unencrypted basic authentication tokens. The impact is limited to credential disclosure rather than remote code execution or service disruption, but it can enable lateral movement if an attacker gains valid credentials. Because the vulnerability is low severity, patching is still recommended if a fix is available; otherwise, enforce secure transport and stronger authentication mechanisms.
OpenCVE Enrichment