CVE-2025-31962 - CERT CVE
ID CVE-2025-31962
Sažetak Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authenticated attacker to gain prolonged unauthorized access to protected API endpoints due to excessive expiration periods.
Reference
CVSS
Base: 2.0
Impact: 1.4
Exploitability:0.5
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW NONE NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
Zadnje važnije ažuriranje 07-01-2026 - 12:17
Objavljeno 07-01-2026 - 12:17