CVE-2025-31981: Hcltech Bigfix Service Management
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data.
Affected products
- Hcltech Bigfix Service Management: version 23.0 only
Published 2026-04-21. Last modified 2026-10-07.