{"id":"CVE-2025-31977","title":"HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.","summary":"HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-311"],"vendor":"hcltech","product":"bigfix_service_management","affected":["bigfix_service_management = 23.0"],"published":"2025-08-28","updated":"2026-09-26","sourceUpdated":"2026-09-26T00:10:00.127","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31977","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631","label":"psirt@hcl.com"}],"tags":["nvd"],"epss":0.00103,"epssPercentile":0.0092,"ingestedAt":"2026-09-26T00:22:39.888Z","slug":"CVE-2025-31977","body":"## Overview\n\nHCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.\n\n## Affected\n\n- `bigfix_service_management = 23.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}