CVE-2025-52627: HCL AION is susceptible to Incorrect Permission Assignment for Critical Resource
Root File System Not Mounted as Read-Only configuration vulnerability. This can allow unintended modifications to critical system files, potentially increasing the risk of system compromise or unauthorized changes.This issue affects AION: 2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52627?
The severity of CVE-2025-52627 is categorized as critical due to the potential for unauthorized modifications to critical system files.
How do I fix CVE-2025-52627?
To fix CVE-2025-52627, ensure that the root filesystem is mounted as read-only to prevent unintended modifications.
What systems are affected by CVE-2025-52627?
CVE-2025-52627 affects the HCL AION product specifically.
What are the risks associated with CVE-2025-52627?
The risks associated with CVE-2025-52627 include potential system compromise and unauthorized changes to critical files.
Is there a workaround for CVE-2025-52627?
Currently, the recommended workaround for CVE-2025-52627 is to configure the filesystem permissions appropriately to limit access.