Cyber Resilience

CVE-2025-31973

Hcltech Bigfix Service Management 23.0

Published
20 May 2026
Modified
24 July 2026
Patch / advisory
CVSS Score v3.1 4.0
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
EPSS Score 0.0018 8th percentile
Risk Priority 31 floored blend · peak EPSS

CVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.

Summary

CVE-2025-31973 is a medium-severity an unspecified weakness vulnerability in Hcltech Bigfix Service Management. Its CVSS base score is 4.0 (Medium).

Operationally, ranked at the 8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially increasing the risk of exploitation in the application environment.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-31982Same product: Hcltech Bigfix Service Management
CVE-2025-31985Same product: Hcltech Bigfix Service Management
CVE-2025-31974Same product: Hcltech Bigfix Service Management
CVE-2025-31978Same product: Hcltech Bigfix Service Management
CVE-2025-31958Same product: Hcltech Bigfix Service Management
CVE-2025-31984Same product: Hcltech Bigfix Service Management
CVE-2025-52613Same product: Hcltech Bigfix Service Management
CVE-2025-31960Same product: Hcltech Bigfix Service Management
CVE-2025-31975Same product: Hcltech Bigfix Service Management
CVE-2025-31959Same product: Hcltech Bigfix Service Management

Affected Assets

hcltech
bigfix service management
23.0

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References