Root File System Misconfiguration in HCL BigFix Service Management
CVE-2025-31974

3.9LOW

What is CVE-2025-31974?

HCL BigFix Service Management is at risk due to a misconfiguration of its root file system, which fails to mount as read-only. This oversight can result in unauthorized modifications to essential system components, potentially leading to vulnerabilities that could be exploited by malicious actors. Maintaining a correctly configured root file system is crucial for ensuring system integrity and protecting against unauthorized access.

Affected Version(s)

BigFix Service Management (SM) 23

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.