Description
HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.
Published: 2026-09-18
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Leakage
Action: Patch Deployment
AI Analysis

Impact

A vulnerability in HCL BigFix Service Management allows an unauthenticated attacker to retrieve internal IP addresses from the application's responses. This disclosure does not compromise credentials or provide direct remote code execution, but it gives sufficient information for an adversary to map the internal network topology and identify potential targets for further attacks.

Affected Systems

The affected product is HCL Software’s HCL BigFix Service Management. No specific product versions are listed in the CVE data, so all deployments of this product that have not applied the vendor’s fix are at risk.

Risk and Exploitability

The CVSS score of 3.1 indicates a low severity impact, and the EPSS score of less than 1% shows a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Because the description states that the attacker is unauthenticated, the likely attack vector is an unauthenticated request to the application, which, if the attacker can reach it, can leak the internal IP addresses.

Generated by OpenCVE AI on September 19, 2026 at 20:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest HCL BigFix Service Management update or patch as released by HCL Software.
  • If a patch is not yet available, limit network access to the application by implementing firewall rules to block unauthenticated external requests from the internet to the vulnerable endpoints.
  • Review network traffic and logs for attempts to request internal IP addresses and investigate any anomalies.

Generated by OpenCVE AI on September 19, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Service Management
Vendors & Products Hcltech
Hcltech bigfix Service Management

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthenticated attacker to extract internal IP addresses from the application's responses, enabling them to map the underlying network topology and identify potential internal targets.
Title HCL BigFix Service Management is affected by multiple security vulnerabilities.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Hcltech Bigfix Service Management
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-09-18T11:11:09.948Z

Reserved: 2026-06-22T13:40:03.377Z

Link: CVE-2026-56597

cve-icon Vulnrichment

Updated: 2026-09-18T11:10:58.607Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:42.017

Modified: 2026-09-18T13:44:57.517

Link: CVE-2026-56597

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor