HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms. An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.
References
| Link | Resource |
|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631 | Vendor Advisory |
Configurations
History
29 Oct 2025, 18:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:* | |
| References | () https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631 - Vendor Advisory | |
| First Time |
Hcltech
Hcltech bigfix Service Management |
28 Aug 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-08-28 17:15
Updated : 2025-10-29 18:12
NVD link : CVE-2025-31977
Mitre link : CVE-2025-31977
CVE.ORG link : CVE-2025-31977
JSON object : View
Products Affected
hcltech
- bigfix_service_management
CWE
CWE-311
Missing Encryption of Sensitive Data
