CVE-2025-31974

LOW

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only

Title source: cna
STIX 2.1

Description

HCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow unintended modifications to critical system components, potentially increasing the risk of system compromise or unauthorized changes.

Scores

CVSS v3 3.9
EPSS 0.0004
EPSS Percentile 11.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1188
Status published
Products (2)
HCL Software/BigFix Service Management (SM) 23
hcltech/bigfix_service_management 23.0
Published May 06, 2026
Tracked Since May 07, 2026