CVE-2025-31981Medium· 5.3▾ SunlitHCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.09%
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access. An attacker with access to the network traffic can sniff packets from the connection and uncover the data.
bigfix_service_management = 23.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-31972Medium· 6.5HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an attacker unauthorized access to sensitive data transmitted between internal components.
CVE-2025-52613Medium· 4.6HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified
CVE-2025-31960Medium· 5.3HCL BigFix Service Management (SM) is vulnerable to information exposure due to improper error handling within its reporting module
CVE-2025-31974Low· 3.9HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only
CVE-2025-31982Low· 3.7HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly
CVE-2025-31983Low· 3.7HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header