Search/CVE-2025-31982
CVE — Low

CVE-2025-31982

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of sensitive functionality.

CVSS v3.1
3.7 LOW
EPSS
0.15%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredLOW
User InteractionREQUIRED
ScopeUNCHANGED
ConfidentialityLOW
IntegrityNONE
AvailabilityLOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:L
Connections
2 relationships
Timeline
disclosure → media coverage
May 6, 2026
Disclosure — published as a CVE record.