CVE-2025-31963 - CERT CVE
ID CVE-2025-31963
Sažetak Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to perform unauthorized configuration changes via unauthenticated administrative configuration requests.
Reference
CVSS
Base: 2.9
Impact: 2.5
Exploitability:0.3
Pristup
VektorSloženostAutentikacija
LOCAL HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
LOW LOW NONE
CVSS vektor CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
Zadnje važnije ažuriranje 07-01-2026 - 12:17
Objavljeno 07-01-2026 - 12:17