HCL AION Offering Images Lack Digital Signature Vulnerability
Vulnerability
A vulnerability exists in HCL AION version 2.0, where offering images are not digitally signed. This lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system.
Impact
The absence of digital signatures on offering images could allow for the introduction of unverified or altered images into the system, raising the risk of integrity issues or unexpected system behavior.
Remediation
Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
