CVE-2025-31964: Hcltech Bigfix Insights For Vulnerability Remediation

Medium severity, CVSS 4.9. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.

Affected products

  • Hcltech Bigfix Insights For Vulnerability Remediation: version 4.2 only

Published 2026-01-07. Last modified 2026-10-07.