Impact
The vulnerability arises from a hardcoded external resource reference and the absence of binary integrity validation. This flaw permits an attacker to replace or tamper with code that the application retrieves, potentially enabling extraction of sensitive information or insertion of malicious logic into the executable. Consequently, the primary risk is a loss of data confidentiality and alteration of the application’s integrity.
Affected Systems
The affected product is HCL BigFix Quantum Risk Analyzer. Vendor information is HCLSoftware. No specific versions are listed, so any running instance of this product may be vulnerable unless already updated.
Risk and Exploitability
The CVSS score of 4.4 signals a moderate severity. EPSS data is unavailable and the issue is not on the CISA KEV list, suggesting a lower current exploitation likelihood, yet the vulnerability enables remote modification or exposure of data simply by controlling the application’s external resource fetching. The likely attack vector is remote via the application’s download capability, inferred from the description.
OpenCVE Enrichment