HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-21 15:16
Updated : 2026-06-17 09:11
NVD link : CVE-2025-31981
Mitre link : CVE-2025-31981
CVE.ORG link : CVE-2025-31981
JSON object : View
Products Affected
hcltech
- bigfix_service_management
CWE
CWE-319
Cleartext Transmission of Sensitive Information
