CVE 4.6 MEDIUM

HCL BigFix Service Management (SM) does not adequately sanitize or safely render_CVE-2025-31978

4.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Description

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.

Basic Information

ID CVE-2025-31978
Source HCL
Published May 6, 2026 at 13:48

Affected Product

Vendor HCL Software
Product BigFix Service Management (SM)
Version 23
Affected Versions HCL Software BigFix Service Management (SM) 23

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.