CVE-2025-31973
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@hcl.com — https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hcltech | bigfix_service_management | 23.0 | |
References
Verify integrity in audit chain (admin only). AS-IS.