CVE-2025-31981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-319 Cleartext Transmission of Sensitive Information
Publication date:
21/04/2026
Last modified:
22/04/2026

Description

HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*