Impact
An unrestricted file upload vulnerability exists in HCL BigFix Service Management due to improper validation of uploaded file types. The flaw allows an unauthenticated attacker to upload arbitrary files and execute them, leading to a full compromise of the affected server. The weakness is a classic file upload flaw (CWE-434).
Affected Systems
The vulnerability affects HCL Software’s HCL BigFix Service Management product. No specific version details are provided, so all installations of this product are considered potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity, while the EPSS score of less than 1% shows a very low expected exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog, implying it is not known to be actively exploited by known threat actors. The most likely attack vector is an unauthenticated user accessing the web interface and using the upload functionality to deliver malicious payloads. An attacker would need no additional credentials, making the initial exploitation straightforward if the upload endpoint is reachable.
OpenCVE Enrichment