Impact
The vulnerability allows an attacker to create multiple simultaneous authenticated sessions for the same administrative account, enabling the prediction or hijacking of valid session identifiers. Once a session is hijacked, the attacker can execute any action with full privileged user permissions, effectively compromising the administrative context.
Affected Systems
HCL Software’s BigFix Service Management product is affected. No specific version information is provided in the available data.
Risk and Exploitability
The CVSS score of 3.1 indicates a low overall risk level, and the EPSS score of 0.00153 (approximately 0.15%) indicates a very low probability of exploitation, suggesting a lack of publicly observed exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is the exploitation of the application’s session management flaw, which could be accessed remotely through the management interface. While the score is low, the impact of a successful session hijack is significant due to the privileged actions that become available to the attacker.
OpenCVE Enrichment