ZeroHour

CVE-2025-31964

CVSS 3.1
4.9 medium
EPSS
<1%p28
Published
()
Modified
Description

Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.

Vendors
hcltech
Products
bigfix insights for vulnerability remediation
Weakness
CWE-200, CWE-419
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.