HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605 | Vendor Advisory |
Configurations
History
22 Apr 2026, 15:09
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Hcltech bigfix Service Management
Hcltech |
|
| CPE | cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:* | |
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605 - Vendor Advisory |
21 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 15:16
Updated : 2026-04-22 15:09
NVD link : CVE-2025-31981
Mitre link : CVE-2025-31981
CVE.ORG link : CVE-2025-31981
JSON object : View
Products Affected
hcltech
- bigfix_service_management
CWE
CWE-319
Cleartext Transmission of Sensitive Information
