CVE-2023-37520: Hcltech Bigfix Platform

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability identified in BigFix Server version 9.5.12.68, allowing for potential data exfiltration. This XSS vulnerability is in the Gather Status Report, which is served by the BigFix Relay.

Affected products

  • Hcltech Bigfix Platform: from 9.5, before 9.5.23 (fixed in 9.5.23); from 10.0.0, before 10.0.10 (fixed in 10.0.10); version 11.0.0 only

Published 2023-12-21. Last modified 2026-06-17.