HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability
HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the internal infrastructure for further targeted attacks.
CVSS Score
2.6
LOW
Published
16 Jul 2026 14:16
Modified
17 Jul 2026 16:27
Vendor
Hcltech
Product
Dfxanalytics
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N
Attack Vector
Network
Complexity
High
Privileges
High
Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
Low
Availability
None
Weaknesses (CWE)
CWE-200
References
Affected Systems
Hcltech
Dfxanalytics
Hcltech
Dfx Server
Dfxanalytics
External Links
KEV Status
Not in CISA KEV catalog