{"id":"CVE-2025-31980","title":"HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstre…","summary":"HCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstre…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","cwe":["CWE-20"],"vendor":"HCL Software","product":"HCL BigFix Service Management","affected":["hcl_bigfix_service_management Version 27"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T20:36:15.187","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31980","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-01T16:33:19.736186Z"},"ingestedAt":"2026-10-01T18:55:42.358Z","epss":0.00164,"epssPercentile":0.05077,"slug":"CVE-2025-31980","body":"## Overview\n\nHCL BigFix Service Management is affected by an Improper Input Validation vulnerability, which could allow an attacker to inject unvalidated, malformed data into the application, enabling potential injection attacks or errors in downstream processing systems.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}