CVE-2022-42451

MEDIUM

Hcltech Bigfix Patch Management - Insufficiently Protected Credentials

Title source: rule

Description

Certain credentials within the BigFix Patch Management Download Plug-ins are stored insecurely and could be exposed to a local privileged user.

Scores

CVSS v3 4.6
EPSS 0.0003
EPSS Percentile 6.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Classification

CWE
CWE-522
Status published

Affected Products (1)

hcltech/bigfix_patch_management < 1055

Timeline

Published Oct 11, 2023
Tracked Since Feb 18, 2026