Impact
HCL BigFix Service Management contains a broken access control flaw that permits a low‑privileged user to reach administrative screens and functions normally reserved for higher roles. The vulnerability is a classic example of the weak Role‑Based Access Control weakness identified as CWE‑285 and can lead to elevation of privileges, compromise of configuration data, and potential system disruption.
Affected Systems
The affected product is HCL Software’s HCL BigFix Service Management. No specific patched versions are listed in the CNA data, and the vendor has not provided detailed affected product versions. Administrators should verify whether their installations correspond to the versions referenced in the vendor’s support documentation.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. With an EPSS score of less than 1%, the probability of exploitation in the wild is low but non‑zero. The vulnerability is not listed in the CISA KEV catalog, so no widespread exploitation has been reported. Exploitation requires legitimate user access; an attacker with a normal user account can navigate to protected administrative interfaces and perform unauthorized actions. No public exploit code is known, but the attack path is straightforward once a valid session exists.
OpenCVE Enrichment