Impact
The vulnerability allows an attacker to infer the existence of specific user accounts on HCL BigFix Platform by observing differences in response times. This information can be used for credential guessing or social engineering, but it does not provide direct access to data or code execution. The weakness corresponds to CWE‑208: Information Exposure Through Inadequate Log Message Filtering.
Affected Systems
HCL Software’s HCL BigFix Platform is the affected product. The CVE data does not specify vulnerable versions, so all deployments of the platform are potentially at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to send requests and monitor response times, typically performing a timing attack to infer account existence. No privilege escalation or remote code execution is possible, but the disclosed information can aid credential guessing or social engineering attacks.
OpenCVE Enrichment