{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-31981","assignerOrgId":"1e47fe04-f25f-42fa-b674-36de2c5e3cfc","state":"PUBLISHED","assignerShortName":"HCL","dateReserved":"2025-04-01T18:46:33.655Z","datePublished":"2026-04-21T14:26:39.400Z","dateUpdated":"2026-04-21T19:28:19.397Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1e47fe04-f25f-42fa-b674-36de2c5e3cfc","shortName":"HCL","dateUpdated":"2026-04-21T14:28:24.452Z"},"title":"HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption","datePublic":"2026-04-20T13:55:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-319","description":"CWE-319 Cleartext transmission of sensitive information","type":"CWE"}]}],"affected":[{"vendor":"HCLSoftware","product":"BigFix Service Management (SM)","versions":[{"status":"affected","version":"23"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.  An attacker with access to the network traffic can sniff packets from the connection and uncover the data.","supportingMedia":[{"type":"text/html","base64":false,"value":"HCL BigFix Service Management (SM) Discovery is vulnerable to unenforced encryption due to port 80 (HTTP) being open, allowing unencrypted access.&nbsp; An attacker with access to the network traffic can sniff packets from the connection and uncover the data.&nbsp;"}]}],"references":[{"url":"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0127605"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-04-21T19:28:07.221158Z","id":"CVE-2025-31981","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-04-21T19:28:19.397Z"}}]}}