CVE-2025-31981 PUBLISHED

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption

Assigner: HCL
Reserved: 01.04.2025 Published: 21.04.2026 Updated: 21.04.2026

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor HCLSoftware
Product BigFix Service Management (SM)
Versions Default: unaffected
  • Version 23 is affected

References

Problem Types

  • CWE-319 Cleartext transmission of sensitive information CWE