Impact
A remote attacker can capture valid authentication data in transit and later resend it, allowing them to impersonate a legitimate user without needing valid credentials. This flaw is an Authentication Bypass (CWE-294) and provides a path to unauthorized access that could permit the convenience of privileged operations on any compromised system. The application’s failure to embed a timestamp or nonce in authentication messages makes this replay straightforward once traffic can be intercepted.
Affected Systems
The HCL Software DFXAnalytics platform is affected. No specific product or version numbers are listed, so any deployed instance of DFXAnalytics that has not yet applied the vendor’s latest patch should be evaluated for this vulnerability.
Risk and Exploitability
The CVSS score of 2.6 signals a low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation under current conditions. The vulnerability is not present in the CISA KEV catalog. Nonetheless, the absence of a timestamp or nonce creates a valid opportunity for remote attackers who can intercept network traffic; if they can replay captured authentication packets before session validation is performed, they may gain unauthorised access. Given the low CVSS but potential for privilege escalation, the risk merits remediation even though large‑scale attacks are unlikely at present.
OpenCVE Enrichment