ZeroHour

CVE-2025-31962

CVSS 3.1
4.3 medium
EPSS
<1%p8
Published
()
Modified
Description

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

Vendors
hcltech
Products
bigfix insights for vulnerability remediation
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.