CVE-2020-14254: Hcltech Bigfix Platform

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can passively record traffic and later decrypt it.

Affected products

  • Hcltech Bigfix Platform: up to and including 10.0.2

Published 2020-12-16. Last modified 2026-06-17.