HCL AION Offering Images Lack Digital Signature Vulnerability

Vulnerability

A vulnerability exists in HCL AION version 2.0, where offering images are not digitally signed. This lack of image signing may allow the use of unverified or tampered images, potentially leading to security risks such as integrity compromise or unintended behavior in the system.

Impact

The absence of digital signatures on offering images could allow for the introduction of unverified or altered images into the system, raising the risk of integrity issues or unexpected system behavior.

Remediation

Users can upgrade to HCL AION version 2.1.2, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.

Added: Mar 16, 2026, 2:42 PM
Updated: Mar 16, 2026, 2:42 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
2.8
remediation
0.0
relevance
4.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.