HCL AION Brute-Force Vulnerability Allowing Repeated Authentication Attempts

Vulnerability

A vulnerability exists in HCL AION v2.1.0 that lacks sufficient protections against brute-force attacks. This weakness may permit repeated authentication attempts, potentially leading to unauthorized access or account compromise under certain conditions.

Impact

Exploitation of this vulnerability could result in unauthorized access to user accounts or systems.

Remediation

Users can upgrade to HCL AION v2.5.0, which addresses this vulnerability. For assistance with the upgrade process, contact the HCL AION support team.

Added: May 14, 2026, 5:47 PM
Updated: May 14, 2026, 5:47 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.3
exploitability
7.4
remediation
0.0
relevance
8.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.