{"id":"CVE-2026-67105","title":"HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of s…","summary":"HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of s…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-319"],"vendor":"HCL Software","product":"HCL BigFix Service Management","affected":["hcl_bigfix_service_management Version 27"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:17:31.237","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-67105","references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015","label":"psirt@hcl.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-01T15:20:22.122219Z"},"ingestedAt":"2026-10-01T15:48:17.815Z","slug":"CVE-2026-67105","body":"## Overview\n\nHCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}