---
id: CVE-2025-59852
title: >-
  HCL  DFXAnalytics  is affected by an Insufficient Transport Layer Protection
  vulnerability where data is transmitted over the network without encryption,
  which could allow an attacker to compromise the confidentiality, integrity,
  and aut…
summary: >-
  HCL  DFXAnalytics  is affected by an Insufficient Transport Layer Protection
  vulnerability where data is transmitted over the network without encryption,
  which could allow an attacker to compromise the confidentiality, integrity,
  and aut…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-319
vendor: hcltech
product: dfxanalytics
affected:
  - dfxanalytics < 4.1
patched:
  - dfxanalytics 4.1
published: '2026-05-06'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59852'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0130569
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00088
epssPercentile: 0.00361
ingestedAt: '2026-09-30T22:27:27.779Z'
---

## Overview

HCL  DFXAnalytics  is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise the confidentiality, integrity, and authentication of sensitive information.

## Affected

- `dfxanalytics < 4.1`

## Remediation

Upgrade past the affected range:

- `dfxanalytics 4.1`
