Low severity2.9NVD Advisory· Published Jan 7, 2026· Updated Jun 17, 2026
CVE-2025-31963
CVE-2025-31963
Description
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
Affected products
3- cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2:*:*:*:*:*:*:*
= 4.2+ 1 more
- (no CPE)range: = 4.2
- (no CPE)range: 4.2
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.