Description
HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.
Published: 2026-07-16
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HCL DFXAnalytics remains vulnerable because it supports deprecated TLS 1.0 and TLS 1.1, protocols with documented cryptographic weaknesses that allow data interception and decryption. If an attacker could observe the network traffic between a client and the DFXAnalytics server, they could exploit these protocols to gain access to confidential information. The weakness is classified as CWE-327, a use of weak cryptographic algorithms.

Affected Systems

The affected product is HCL Software's DFXAnalytics. No version details are provided in the CNA data; therefore all deployed instances that still allow TLS 1.0 or TLS 1.1 connections are potentially vulnerable.

Risk and Exploitability

The CVSS base score of 5.9 indicates a medium severity. The EPSS score of 0.00137 suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A likely attack vector is a network adversary capable of eavesdropping on traffic between clients and the DFXAnalytics server; this inference is based on the description that the attack relies on observing traffic protected by weak TLS versions.

Generated by OpenCVE AI on July 31, 2026 at 01:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Modify the DFXAnalytics configuration to disable support for TLS 1.0 and TLS 1.1, enabling only TLS 1.2 or TLS 1.3.
  • Configure the application to use strong cipher suites that exclude known weak algorithms, ensuring that TLS 1.2/1.3 are used with robust encryption.
  • Establish automated monitoring or regular scanning of network connections to verify that only secure TLS versions and ciphers are in use, and set alerts for any detection of legacy protocols.

Generated by OpenCVE AI on July 31, 2026 at 01:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech dfxanalytics
Vendors & Products Hcltech
Hcltech dfxanalytics

Thu, 16 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all support for TLS 1.0 and TLS 1.1, and exclusively enable support for secure protocols, specifically TLS 1.2 and TLS 1.3.
Title HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.
Weaknesses CWE-327
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Hcltech Dfxanalytics
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-07-16T13:41:57.396Z

Reserved: 2026-06-22T13:38:32.649Z

Link: CVE-2026-56454

cve-icon Vulnrichment

Updated: 2026-07-16T13:41:20.648Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T02:00:05Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm