{"id":"CVE-2025-31981","title":"HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and …","summary":"HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and …","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-319"],"vendor":"hcltech","product":"bigfix_service_management","affected":["bigfix_service_management = 23.0"],"published":"2026-04-21","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:10:00.273","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-31981","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605","label":"psirt@hcl.com"}],"tags":["nvd"],"epss":0.00087,"epssPercentile":0.00346,"ingestedAt":"2026-09-30T22:27:27.765Z","slug":"CVE-2025-31981","body":"## Overview\n\nHCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.\n\n## Affected\n\n- `bigfix_service_management = 23.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}