---
id: CVE-2025-31981
title: "HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.\_ An attacker with access to the network traffic can sniff packets from the connection and …"
summary: "HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.\_ An attacker with access to the network traffic can sniff packets from the connection and …"
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-319
vendor: hcltech
product: bigfix_service_management
affected:
  - bigfix_service_management = 23.0
published: '2026-04-21'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-31981'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00087
epssPercentile: 0.00346
ingestedAt: '2026-09-30T22:27:27.765Z'
---

## Overview

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

## Affected

- `bigfix_service_management = 23.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
