8.2
CVE-2026-35149
- EPSS 0.25%
- Veröffentlicht 16.07.2026 11:03:06
- Zuletzt bearbeitet 21.07.2026 20:16:44
- Erkennungen
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Dfx Server Version <= 2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.161 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| psirt@hcl.com | 8.2 | 3.9 | 4.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
|
CWE-294 Authentication Bypass by Capture-replay
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0131782