CVE-2025-31964
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Scoring
- Severity
- LOW
- CVSS base score
- 2.2
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L
- EPSS probability
- 0.35%
- CWE
- CWE-200, CWE-419
- Published
- 2026-01-07
- Last modified
- 2026-03-12
Affected products
- HCLSoftware BigFix IVR
Weakness type
Related vulnerabilities
- CVE-2026-88059 — Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
- CVE-2026-88013 — rclone: http backend forwards custom/auth headers to a different host on redirect
- CVE-2026-88893 — OpenPanel Unauthenticated Share Lookup Information Disclosure
- CVE-2026-88876 — AVideo PlayerSkins seo.php Missing Authorization Password-Protected VOD
- CVE-2026-88874 — AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 Authentication Bypass
- CVE-2026-0305 — Prisma Access Agent: Information Disclosure Vulnerability on Linux
- CVE-2026-87017 — Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
- CVE-2026-86767 — Snipe-IT before 8.7.0 Cross-Company Read via requested-assets