6.3
CVE-2026-35146
- EPSS 0.12%
- Veröffentlicht 16.07.2026 11:01:08
- Zuletzt bearbeitet 21.07.2026 20:10:44
- Erkennungen
HCL DFXServer is affected by an Unencrypted Communication vulnerability.
HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted between the user and the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Dfx Server Version <= 2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.019 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@hcl.com | 6.3 | 2.8 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782