CVE-2025-31963: HCL BigFix IVR is impacted by improper authentication and missing CSRF protection
Published Jan 7, 2026
·Updated
Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
Affected Software
2 affected components
HCL BigFix IVR
hcltech Bigfix Insights For Vulnerability Remediation=4.2
Event History
Jan 7, 2026
CVE Published
via MITRE·07:05 AM
Data Sourced
via MITRE·07:05 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-31963?
CVE-2025-31963 has a medium severity rating due to its potential for unauthorized configuration changes.
2
How do I fix CVE-2025-31963?
To fix CVE-2025-31963, ensure proper authentication measures and implement CSRF protection in the local setup interface.
3
Who is affected by CVE-2025-31963?
CVE-2025-31963 affects users of HCL BigFix IVR version 4.2.
4
What type of vulnerability is CVE-2025-31963?
CVE-2025-31963 is an improper authentication and missing CSRF protection vulnerability.
5
Can a remote attacker exploit CVE-2025-31963?
No, CVE-2025-31963 can only be exploited by local attackers due to its nature.