CVE-2024-23583

MEDIUM

Hcltech Bigfix Platform - Insufficiently Protected Credentials

Title source: rule

Description

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Scores

CVSS v3 6.7
EPSS 0.0007
EPSS Percentile 22.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-522
Status published

Affected Products (2)

hcltech/bigfix_platform < 9.5.25
hcltech/bigfix_platform

Timeline

Published May 17, 2024
Tracked Since Feb 18, 2026