HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
History

Tue, 15 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
Description HCL BigFix Web Reports' service communicates over HTTPS but exhibits a weakness in its handling of SSL certificate validation. This scenario presents a possibility of man-in-the-middle (MITM) attacks and data exposure as, if exploited, this vulnerability could potentially lead to unauthorized access.
Title HCL BigFix Web Reports is susceptible to a Man-In-The-Middle (MITM) attack
Weaknesses CWE-295
References
Metrics cvssV4_0

{'score': 2.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published: 2025-04-15T18:16:01.247Z

Updated: 2025-04-15T18:51:09.135Z

Reserved: 2024-07-29T21:32:08.371Z

Link: CVE-2024-42193

cve-icon Vulnrichment

Updated: 2025-04-15T18:49:59.910Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-15T19:16:06.800

Modified: 2025-04-16T13:25:59.640

Link: CVE-2024-42193

cve-icon Redhat

No data.