CVE-2025-31973
MEDIUMHCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'
Title source: cnaDescription
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
References (1)
Core 1
Scores
CVSS v3
4.0
EPSS
0.0003
EPSS Percentile
7.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1395
Status
published
Products (2)
HCL/BigFix Service Management (SM)
23
hcltech/bigfix_service_management
23.0
Published
May 20, 2026
Tracked Since
May 20, 2026