HCL DFXAnalytics Login Replay Attack Vulnerability

Vulnerability

A login replay attack vulnerability has been identified in HCL DFXAnalytics versions 3.0 and below. This vulnerability allows remote attackers to intercept, delay, or fraudulently retransmit valid authentication data, potentially leading to unauthorized access. The issue arises because the application does not include timestamps with authentication messages, allowing outdated messages to be accepted as valid.

Impact

Exploitation of this vulnerability could result in unauthorized access to user accounts by allowing attackers to replay authentication data.

Remediation

Users can upgrade to HCL DFXAnalytics version 4.1, where this vulnerability has been successfully mitigated.

Added: Jul 16, 2026, 2:36 PM
Updated: Jul 16, 2026, 2:36 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
6.2
remediation
0.0
relevance
9.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.