CVE-2025-31977

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*

History

29 Oct 2025, 18:12

Type Values Removed Values Added
CPE cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*
References () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631 - () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631 - Vendor Advisory
First Time Hcltech
Hcltech bigfix Service Management

28 Aug 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-28 17:15

Updated : 2025-10-29 18:12


NVD link : CVE-2025-31977

Mitre link : CVE-2025-31977

CVE.ORG link : CVE-2025-31977


JSON object : View

Products Affected

hcltech

  • bigfix_service_management
CWE
CWE-311

Missing Encryption of Sensitive Data