Low severity2.2NVD Advisory· Published Jan 7, 2026· Updated Jun 17, 2026
CVE-2025-31964
CVE-2025-31964
Description
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Affected products
34.2+ 1 more
- (no CPE)range: 4.2
- (no CPE)range: 4.2
- cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- support.hcl-software.com/csmnvdVendor Advisory
News mentions
0No linked articles in our index yet.