Cryptographic Weakness in HCL BigFix SM Allows Potential Exploitation
CVE-2025-31977

5.3MEDIUM

Key Information:

Vendor
CVE Published:
28 August 2025

What is CVE-2025-31977?

HCL BigFix SM is susceptible to a vulnerability stemming from weak or outdated encryption algorithms. This cryptographic weakness enables an attacker with network access to potentially decrypt or manipulate sensitive encrypted communications under specific circumstances. Proper encryption protocols are essential to ensure the integrity and confidentiality of data transmitted over networks.

Affected Version(s)

BigFix Service Management (SM) 23

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31977 : Cryptographic Weakness in HCL BigFix SM Allows Potential Exploitation