Home

Description

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

PUBLISHED Reserved 2025-04-01 | Published 2026-04-21 | Updated 2026-04-21 | Assigner HCL




MEDIUM: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-319 Cleartext transmission of sensitive information

Product status

Default status
unaffected

23
affected

References

support.hcl-software.com/...rticle&sysparm_article=KB0127605

cve.org (CVE-2025-31981)

nvd.nist.gov (CVE-2025-31981)

Download JSON