CVE-2025-52645: HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification.
HCL AION is affected by a vulnerability where model packaging and distribution mechanisms may not include sufficient authenticity verification. This may allow the possibility of unverified or modified model artifacts being used, potentially leading to integrity concerns or unintended behaviour.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52645?
CVE-2025-52645 is rated as a medium severity vulnerability due to insufficient authenticity verification in model packaging and distribution.
How do I fix CVE-2025-52645?
To fix CVE-2025-52645, ensure that the model packaging and distribution mechanisms include robust authenticity verification processes.
What impact does CVE-2025-52645 have on HCL AION?
CVE-2025-52645 can lead to unverified model distributions, potentially allowing unauthorized modifications or malicious alterations.
Is CVE-2025-52645 exploitable?
Yes, CVE-2025-52645 is potentially exploitable, allowing attackers to distribute unverified models to users.
Where can I find more information about CVE-2025-52645?
Further details regarding CVE-2025-52645 can typically be found in official HCL documentation and security advisories.