CVE-2025-31959
CVE-2025-31959 is a low-severity vulnerability in Hcltech Bigfix Service Management with a CVSS 3.x base score of 3.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-1230.
Key facts
- Severity: Low (CVSS 3.x base score 3.5)
- EPSS exploit prediction: 0% (3rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-209688
- Weakness: CWE-1230
- Affected product: Hcltech Bigfix Service Management
- Published:
- Last modified:
Description
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
Frequently asked questions
- What is CVE-2025-31959?
- HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- How severe is CVE-2025-31959?
- CVE-2025-31959 has a CVSS 3.x base score of 3.5, rated low severity. It is exploitable over network with low attack complexity, requires low privileges and user interaction. Impact on confidentiality is low, integrity none, and availability none.
- Is CVE-2025-31959 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (3rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-31959?
- CVE-2025-31959 affects Hcltech Bigfix Service Management. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2025-31959?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-31959 have an EU (EUVD) identifier?
- Yes. CVE-2025-31959 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-209688.
- When was CVE-2025-31959 published?
- CVE-2025-31959 was published on 2026-05-06 and last updated on 2026-09-30.
References
Affected products (1)
- cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:*
More vulnerabilities in Hcltech Bigfix Service Management
- CVE-2024-30151 — High (CVSS 8.3): HCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege…
- CVE-2026-67105 — High (CVSS 7.4): HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker…
- CVE-2026-56589 — High (CVSS 7.2): HCL BigFix Service Management is affected by a Stored Cross-Site Scripting (XSS) vulnerability, which could allow an…
- CVE-2025-31972 — Medium (CVSS 6.5): HCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS…
- CVE-2026-67171 — Medium (CVSS 5.3): HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint…
- CVE-2026-67106 — Medium (CVSS 5.3): HCL BigFix Service Management is affected by an Information Disclosure vulnerability because two exposed API endpoints…
All CVEs affecting Hcltech Bigfix Service Management →
Other CWE-1230 vulnerabilities
- CVE-2024-9099 — High (CVSS 8.1): In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all…
- CVE-2025-13084 — High (CVSS 7.6): The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys.…
- CVE-2025-47324 — High (CVSS 7.5): Information disclosure while accessing and modifying the PIB file of a remote device via powerline.
- CVE-2025-0330 — High (CVSS 7.5): In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error…
- CVE-2024-53291 — High (CVSS 7.5): Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An…
- CVE-2025-30038 — High (CVSS 7.3): The vulnerability consists of a session ID leak when saving a file downloaded from CGM CLININET. The identifier is…