Description
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
Published: 2026-07-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL DFXServer permits connections over plain HTTP, allowing an attacker to capture and read traffic that passes between users and the application. This weakness is classified as CWE-326, Weak Encryption. This can reveal confidential data such as authentication credentials, configuration information, and business data. The weakness arises from the lack of encryption and does not involve code execution or privilege escalation.

Affected Systems

All releases of HCLSoftware's DFXServer are affected. No specific version range is listed, so the entire product line should be considered vulnerable until a patch is issued.

Risk and Exploitability

The CVSS score of 6.3 indicates a moderate risk. With an EPSS score of < 1%, the likelihood of exploitation is very low. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a remote attacker intercepting network traffic on the same network or over transit routes; such an interception requires network access but no special application privileges.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure DFXServer to use HTTPS/TLS and disable the HTTP endpoint.
  • Apply the latest HCLSoftware patch that removes support for unencrypted connections.
  • If a patch cannot be applied immediately, block HTTP traffic to the server with firewall or network segmentation rules.

Generated by OpenCVE AI on July 31, 2026 at 02:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware dfxserver
Vendors & Products Hclsoftware
Hclsoftware dfxserver

Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
Title HCL DFXServer is affected by an Unencrypted Communication vulnerability.
Weaknesses CWE-326
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}


Subscriptions

Hclsoftware Dfxserver
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T12:14:36.987Z

Reserved: 2026-04-01T16:32:01.021Z

Link: CVE-2026-35146

cve-icon Vulnrichment

Updated: 2026-07-16T12:14:30.817Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:15:06Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength