CVE-2025-31973

critical
Published 2026-05-20 · Modified 2026-05-20
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.8

Description

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@hcl.com — https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144

Application impact

VendorProductVersionsFixed
hcltechbigfix_service_management23.0

References

Verify integrity in audit chain (admin only). AS-IS.