Impact
HCL BigFix Service Management suffers from an improper authentication flaw caused by inadequate account lockouts, allowing an unauthenticated attacker to conduct sustained brute‑force attempts against the login interface. The weakness, identified as CWE‑307, could compromise confidentiality, integrity, or availability by enabling unauthorized access to the system. The vulnerability directly increases the risk of unauthorized system intrusion without any initial authentication.
Affected Systems
HCL Software’s HCL BigFix Service Management product is affected. No specific version range is listed in the advisory, so administrators should verify all deployed instances against the vendor support information.
Risk and Exploitability
The CVSS score of 6.5 denotes a medium severity impact, and the EPSS score is reported as less than 1%, indicating a low probability of exploitation at this time. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector is the network‑facing login interface and can be leveraged by remote attackers to perform brute‑force attacks without prior authentication.
OpenCVE Enrichment