CVE-2023-37523: Hcltechsw Bigfix Bare Osd Metal Server Webui

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Missing or insecure tags in the HCL BigFix Bare OSD Metal Server WebUI version 311.19 or lower could allow an attacker to execute a malicious script on the user's browser.

Affected products

  • Hcltechsw Bigfix Bare Osd Metal Server Webui: up to and including 311.19

Published 2024-01-16. Last modified 2026-06-17.