Impact
HCL DFXServer exposes an authentication bypass vulnerability that allows an adversary without valid credentials to gain access by intercepting and modifying the server’s authentication responses. The flaw is a process and input‑related weakness classified as CWE‑294, enabling a malicious user to alter response data so the server accepts unauthorized tokens or credentials.
Affected Systems
The vulnerability affects HCL Software’s DFXServer product. No version‑specific information is supplied, implying that all currently deployed releases could be susceptible until the vendor releases an official fix.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves intercepting traffic between a client and the DFXServer—such as through man‑in‑the‑middle techniques or unauthorized proxies—to modify authentication responses. An attacker needs network access to the communication path but does not require elevated privileges on the server to exploit the flaw.
OpenCVE Enrichment