---
id: CVE-2025-31977
title: "HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.\_ An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions."
summary: "HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.\_ An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions."
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-311
vendor: hcltech
product: bigfix_service_management
affected:
  - bigfix_service_management = 23.0
published: '2025-08-28'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31977'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0123631
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00103
epssPercentile: 0.0092
ingestedAt: '2026-09-26T00:22:39.888Z'
---

## Overview

HCL BigFix SM is affected by cryptographic weakness due to weak or outdated encryption algorithms.  An attacker with network access could exploit this weakness to decrypt or manipulate encrypted communications under certain conditions.

## Affected

- `bigfix_service_management = 23.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
