CVE-2025-31964: HCL BigFix IVR is impacted by an improper service binding configuration
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31964?
CVE-2025-31964 is classified as a critical vulnerability due to its potential impact on service availability from unauthorized access to administrative services.
How do I fix CVE-2025-31964?
To mitigate CVE-2025-31964, reconfigure the service binding settings to ensure administrative services are bound only to the local authentication interface.
Who is affected by CVE-2025-31964?
CVE-2025-31964 affects users of HCL BigFix IVR version 4.2, particularly those with misconfigured service bindings.
What can an attacker do with CVE-2025-31964?
An attacker exploiting CVE-2025-31964 can impact service availability by accessing administrative services exposed to external network interfaces.
Is there a patch available for CVE-2025-31964?
As of now, check HCL's official communication for any patches or updates addressing CVE-2025-31964 and follow their guidance.