SSL Certificate Validation Vulnerability in HCL BigFix Web Reports
CVE-2024-42193

2.1LOW

Key Information:

Vendor
HCL Software Software
Status
HCL Software Bigfix Platform
Vendor
CVE Published:
15 April 2025

Summary

The HCL BigFix Web Reports service, while communicating over HTTPS, shows a significant flaw in its SSL certificate validation process. This vulnerability creates a potential entry point for man-in-the-middle (MITM) attacks, where an attacker can intercept and manipulate data being transmitted. Exploitation of this flaw could allow unauthorized access to sensitive information, posing a serious risk to data integrity and confidentiality.

Affected Version(s)

HCL BigFix Platform 10.0 - 10.0.12; 11.0.0 - 11.0.3

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.