PT-2026-33984 · Hclsoftware · Bigfix Service Management

Published

2026-04-21

·

Updated

2026-04-21

·

CVE-2025-31981

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-31981

Affected Products

Bigfix Service Management