Impact
The vulnerability is a classic buffer overflow (CWE‑121) caused by inadequate validation of input sizes in HCL DFXAnalytics. When an attacker supplies data larger than the application expects, the overflowing payload writes beyond the bounds of a memory buffer, corrupting adjacent memory and eventually causing the process to crash or become unresponsive. This results in a denial of service that undermines the availability of the affected service.
Affected Systems
The impacted product is HCL Software DFXAnalytics. The advisory does not list specific affected versions, so any deployment of this application—particularly those still running the current release described in the CVE—should be considered vulnerable until a patch or mitigation is applied.
Risk and Exploitability
A CVSS score of 5.3 indicates moderate severity, while an EPSS score of < 1 % signals a very low probability of exploitation. Based on the description, it is inferred that the flaw can be triggered remotely by sending a crafted payload over a network interface, such as a web service or API endpoint. Because the vulnerability leads only to a crash with no code execution, the direct impact is limited to service downtime, though repeated attacks could disrupt business continuity. This issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment