4.6
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Description
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.
Basic Information
ID
CVE-2025-31978
Source
HCL
Published
May 6, 2026 at 13:48
Affected Product
Vendor
HCL Software
Product
BigFix Service Management (SM)
Version
23
Affected Versions
HCL Software BigFix Service Management (SM) 23