CVE-2023-28016: Hcltech Bigfix Osd Bare Metal Server

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.

Affected products

  • Hcltech Bigfix Osd Bare Metal Server: up to and including 311.12

Published 2023-06-22. Last modified 2026-06-17.