Medium severity5.7NVD Advisory· Published May 18, 2024· Updated Jun 17, 2026
CVE-2024-23554
CVE-2024-23554
Description
Cross-Site Request Forgery (CSRF) on Session Token vulnerability that could potentially lead to Remote Code Execution (RCE).
Affected products
3cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*range: >=9.5,<9.5.25
- cpe:2.3:a:hcltech:bigfix_platform:11.0.1:*:*:*:*:*:*:*
- Range: 9.5 - 9.5.24, 10 - 10.0.11, 11.0.1
Patches
Vulnerability mechanics
References
1- support.hcltechsw.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.