Improper Service Binding in HCL BigFix IVR Affects Access Security
CVE-2025-31964

2.2LOW

Key Information:

Vendor
CVE Published:
7 January 2026

What is CVE-2025-31964?

HCL BigFix IVR version 4.2 contains a vulnerability that stems from improper configuration of service bindings within its internal service components. This flaw enables privileged attackers to disrupt service availability by making administrative services accessible through external network interfaces instead of restricting them to local authentication interfaces. Such exposure significantly increases the risk of unauthorized access and potential exploitation of administrative functions.

Affected Version(s)

BigFix IVR 4.2

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.