CVE-2025-55252: HCL AION is affected by a Weak Password Policy vulnerability
Published Jan 19, 2026
·Updated
HCL AION version 2 is affected by a Weak Password Policy vulnerability. This can allow the use of easily guessable passwords, potentially resulting in unauthorized access
Affected Software
2 affected components
HCL AION
hcltech Aion=2.0.0
Event History
Jan 19, 2026
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55252?
CVE-2025-55252 is classified as a medium severity vulnerability due to its potential for unauthorized access through weak password policies.
2
How do I fix CVE-2025-55252?
To fix CVE-2025-55252, implement a strong password policy that enforces complexity requirements and regularly update user passwords.
3
What software is affected by CVE-2025-55252?
CVE-2025-55252 affects HCL AION version 2.
4
What are the potential consequences of CVE-2025-55252?
The consequence of CVE-2025-55252 includes the risk of unauthorized access to user accounts due to easily guessable passwords.
5
How can I check if my system is vulnerable to CVE-2025-55252?
You can check if your system is vulnerable to CVE-2025-55252 by reviewing your password policy settings in HCL AION version 2.