Impact
HCL DFXAnalytics remains vulnerable because it supports deprecated TLS 1.0 and TLS 1.1, protocols with documented cryptographic weaknesses that allow data interception and decryption. If an attacker could observe the network traffic between a client and the DFXAnalytics server, they could exploit these protocols to gain access to confidential information. The weakness is classified as CWE-327, a use of weak cryptographic algorithms.
Affected Systems
The affected product is HCL Software's DFXAnalytics. No version details are provided in the CNA data; therefore all deployed instances that still allow TLS 1.0 or TLS 1.1 connections are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 5.9 indicates a medium severity. The EPSS score of 0.00137 suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. A likely attack vector is a network adversary capable of eavesdropping on traffic between clients and the DFXAnalytics server; this inference is based on the description that the attack relies on observing traffic protected by weak TLS versions.
OpenCVE Enrichment