Insufficiently Protected Credentials in HCL BigFix Service Management
CVE-2025-31976

4.8MEDIUM

What is CVE-2025-31976?

HCL BigFix Service Management is affected by a vulnerability that allows for insufficiently protected credentials during communication with a backend application. This transient exposure could put those credentials at risk of exfiltration and misuse by an attacker, highlighting the need for robust credential protection mechanisms to safeguard against potential security incidents.

Affected Version(s)

BigFix Service Management (SM) 23

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.