Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Metrics
Affected Vendors & Products
References
History
Wed, 21 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2:*:*:*:*:*:*:* |
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Insights For Vulnerability Remediation |
|
| Vendors & Products |
Hcltech
Hcltech bigfix Insights For Vulnerability Remediation |
Wed, 07 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface. | |
| Title | HCL BigFix IVR is impacted by an improper service binding configuration | |
| Weaknesses | CWE-200 CWE-419 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2026-01-07T07:18:27.569Z
Updated: 2026-01-07T16:12:56.931Z
Reserved: 2025-04-01T18:46:23.152Z
Link: CVE-2025-31964
Updated: 2026-01-07T14:47:47.938Z
Status : Analyzed
Published: 2026-01-07T12:17:01.993
Modified: 2026-01-21T21:58:36.643
Link: CVE-2025-31964
No data.