Impact
A vulnerability in HCL BigFix Service Management allows an unauthenticated attacker to retrieve internal IP addresses from the application's responses. This disclosure does not compromise credentials or provide direct remote code execution, but it gives sufficient information for an adversary to map the internal network topology and identify potential targets for further attacks.
Affected Systems
The affected product is HCL Software’s HCL BigFix Service Management. No specific product versions are listed in the CVE data, so all deployments of this product that have not applied the vendor’s fix are at risk.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity impact, and the EPSS score of less than 1% shows a very low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Because the description states that the attacker is unauthenticated, the likely attack vector is an unauthenticated request to the application, which, if the attacker can reach it, can leak the internal IP addresses.
OpenCVE Enrichment