Showing 3 vulnerabilities on this page for BigFix IVR

Signals CISA KEV Ransomware Nuclei
HCLSoftware vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

HCL BigFix IVR is impacted by an improper service binding configuration

Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.

CWE-200CWE-419Jan 7, 2026
CVSS2.2v3.1EPSS0.324%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

HCL BigFix IVR is impacted by improper authentication and missing CSRF protection

Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.

CWE-306CWE-352Jan 7, 2026
CVSS2.9v3.1EPSS0.085%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

HCL BigFix IVR is impacted by an insufficient session expiration vulnerability

Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.

CWE-613Jan 7, 2026
CVSS2.0v3.1EPSS0.161%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX