What is CVE-2025-52640?
A vulnerability in HCL AION arises from shared storage architected without sufficient access separation between product components. This could allow processes to access or modify files beyond their intended scope, potentially leading to unintended behavior or security incidents. Applying the vendor-supplied security update is recommended.
Azərbaycanca: HCL AION məhsulunda komponentlərin ortaq istifadə etdiyi yaddaş anbarında kifayət qədər giriş ayrımı təmin edilmədiyi üçün təhlükəsizlik zəifliyi aşkarlanıb. Bu, proseslərin nəzərdə tutulandan kənar fayllara daxil olmasına və ya onları dəyişdirməsinə səbəb ola bilər. Məhsul istehsalçısı tərəfindən buraxılmış təhlükəsizlik yeniləməsinin tətbiq edilməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which product is affected by CVE-2025-52640?
It affects the HCL AION product.
What is the root cause of this vulnerability?
The root cause is shared storage architected without sufficient access separation between product components.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.