CVE-2025-31972EPSS p0.6%

CVE-2025-31972CVE-2025-31972

hcltech / bigfix_service_management

Description

HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.

Scoring

CVSS 6.5 ()
VectorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS0.09% probability of exploitation · percentile 0.6% · 2026-10-04T12:00:21Z
Last modified2026-09-26
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.