Impact
HCL AION exposes certain endpoints without sufficient anti‑automation controls, allowing automated or scripted requests to bypass normal rate limiting or challenge mechanisms. This can lead to unintended behavior, operational disruption, or other security impacts if the server processes excessive or malicious traffic.
Affected Systems
The affected product is HCL Software AION; no specific version information was supplied. Users should verify whether their deployment matches the vulnerability scope described in the vendor reference and consult the support article for update details.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity, and the lack of an EPSS score leaves the exact exploitation likelihood uncertain. Since the issue involves unauthenticated automated traffic, an attacker can remotely abuse exposed endpoints by sending prolonged or bulk requests, potentially causing unintended behavior or degradation of service. The vulnerability is not listed in CISA KEV, but because the attack can be performed over the network it remains a significant concern for environments with exposed AION instances.
OpenCVE Enrichment