Improper Service Binding in HCL BigFix IVR Affects Access Security
CVE-2025-31964
2.2LOW
What is CVE-2025-31964?
HCL BigFix IVR version 4.2 contains a vulnerability that stems from improper configuration of service bindings within its internal service components. This flaw enables privileged attackers to disrupt service availability by making administrative services accessible through external network interfaces instead of restricting them to local authentication interfaces. Such exposure significantly increases the risk of unauthorized access and potential exploitation of administrative functions.
Affected Version(s)
BigFix IVR 4.2
