7.4

CVE-2026-67105

HCL BigFix Service Management is affected by multiple security vulnerabilities.

HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Bigfix Service Management Version 27 Update -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.04
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@hcl.com 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-319 Cleartext Transmission of Sensitive Information

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015
Vendor Advisory