CVE-2025-52631
EUVD-2025-20668003.02.2026, 19:16
HCL AION is affected by a Missing or Insecure HTTP Strict-Transport-Security (HSTS) Header vulnerability. This can allow insecure connections, potentially exposing the application to man-in-the-middle and protocol downgrade attacks.. This issue affects AION: 2.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hcltech | aion | 2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration