Impact
The flaw in HCL DFXServer causes the server to skip authentication checks when certain API endpoints are called. Because the identity is not verified, an attacker can invoke privileged operations without credentials. This is a broken authentication weakness classified as CWE‑639 and can lead to unauthorized system modifications or data exposure.
Affected Systems
HCL Software’s DFXServer is affected. No specific version ranges are listed, so any installation that has not received the vendor’s fix for the authentication bug remains vulnerable. The vulnerability applies to all deployments where the unprotected API environment.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is over the network: a remote attacker can reach the exposed API endpoints and send requests without authentication. Existence of the flaw means that no privileged host access is required; any network user with API reach can exploit it. Because no exploit code is publicly available, the practical risk depends on exposure, but the ease of triggering the missing auth check makes it a priority for remediation.
OpenCVE Enrichment