Vulnerability Details CVE-2025-31964
Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service availability via exposure of administrative services bound to external network interfaces instead of the local authentication interface.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.7%
CVSS Severity
CVSS v3 Score 2.2
Products affected by CVE-2025-31964
-
cpe:2.3:a:hcltech:bigfix_insights_for_vulnerability_remediation:4.2