# CVE-2024-42213

## Summary

- **CVE ID:** CVE-2024-42213
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **CWE:** CWE-531
- **Published:** May 5, 2025
- **Last Modified:** Mar 13, 2026

## Description

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment.  An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.

## Affected Products

- HCL Software — HCL BigFix Compliance (2.0.12)

## References

- [CNA](https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120961)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.29%
- **EPSS Percentile:** 21.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._