Impact
HCL DFXServer permits connections over plain HTTP, allowing an attacker to capture and read traffic that passes between users and the application. This weakness is classified as CWE-326, Weak Encryption. This can reveal confidential data such as authentication credentials, configuration information, and business data. The weakness arises from the lack of encryption and does not involve code execution or privilege escalation.
Affected Systems
All releases of HCLSoftware's DFXServer are affected. No specific version range is listed, so the entire product line should be considered vulnerable until a patch is issued.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate risk. With an EPSS score of < 1%, the likelihood of exploitation is very low. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a remote attacker intercepting network traffic on the same network or over transit routes; such an interception requires network access but no special application privileges.
OpenCVE Enrichment