HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network ac…
cve CVE-2026-67105 2 sources, 2 claims · Watch
NVD writes:
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. the claim
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. the claim
- Severity
- high GitHub advisoriesHIGH NVD
- CVSS
- 7.4 GitHub advisories7.4 NVD
- Vendor
- HCL Software NVD
- Product
- HCL BigFix Service Management NVD
- CWE
- CWE-319 GitHub advisoriesCWE-319 NVD
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2026-10-01 | first spoke of it: HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could... | GitHub advisories |
| 2026-10-01 | first spoke of it: HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. | NVD |
HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.
What it is to other things
| affects | hcltech/bigfix_service_management NVD |
| made_by | hcltech NVD |
In words only, so not counted until a person confirms one:
| made_by | hcl_softwareNVD says “HCL Software” |
| affects | hcl_software/hcl_bigfix_service_managementNVD says “HCL Software · HCL BigFix Service Management” |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | no At least one of those steps needs a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | GitHub advisories | 7.4receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67105",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-319",
"name": "Cleartext Transmission of Sensitive Information"
}
],
"description": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.",
"ghsa_id": "GHSA-xqgc-v2f3-h4v3",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xqgc-v2f3-h4v3"
},
{
"type": "CVE",
"value": "CVE-2026-67105"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67105",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-xqgc-v2f3-h4v3"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CVSS cvss | NVD | 7.4receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:Nreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | GitHub advisories | CWE-319receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67105",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-319",
"name": "Cleartext Transmission of Sensitive Information"
}
],
"description": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.",
"ghsa_id": "GHSA-xqgc-v2f3-h4v3",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xqgc-v2f3-h4v3"
},
{
"type": "CVE",
"value": "CVE-2026-67105"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67105",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-xqgc-v2f3-h4v3"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| CWE cwe | NVD | CWE-319receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | HCL BigFix Service Managementreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | GitHub advisories | high From 7.0 to 8.9. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-67105",
"cvss": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_severities": {
"cvss_v3": {
"score": 7.4,
"vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
"cvss_v4": {
"score": 0.0,
"vector_string": null
}
},
"cwes": [
{
"cwe_id": "CWE-319",
"name": "Cleartext Transmission of Sensitive Information"
}
],
"description": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.",
"ghsa_id": "GHSA-xqgc-v2f3-h4v3",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-xqgc-v2f3-h4v3"
},
{
"type": "CVE",
"value": "CVE-2026-67105"
}
],
"nvd_published_at": "2026-10-01T15:17:31Z",
"published_at": "2026-10-01T15:30:42Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-67105",
"https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015",
"https://github.com/advisories/GHSA-xqgc-v2f3-h4v3"
],
"repository_advisory_url": null,
"severity": "high",
"source_code_location": "",
"summary": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could...",
"type": "unreviewed",
"updated_at": "2026-10-01T15:30:50Z",
"url": "https://api.github.com/advisories/GHSA-xqgc-v2f3-h4v3",
"vulnerabilities": [],
"withdrawn_at": null
} | — | ||||
| Severity severity | NVD | HIGH From 7.0 to 8.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | total The attacker gains full control of the component, or all of its information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | HCL Softwarereceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"defaultStatus": "unaffected",
"product": "HCL BigFix Service Management",
"vendor": "HCL Software",
"versions": [
{
"status": "affected",
"version": "Version 27"
}
]
}
],
"source": "psirt@hcl.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hcltech:bigfix_service_management:27:-:*:*:*:*:*:*",
"matchCriteriaId": "08B2E58A-98AF-44B9-A25D-84B0A4B209CC",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks."
}
],
"id": "CVE-2026-67105",
"lastModified": "2026-10-05T17:25:08.347",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.4,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"exploitabilityScore": 2.2,
"impactScore": 5.2,
"source": "psirt@hcl.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-67105",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:20:22.122219Z",
"version": "2.0.3"
}
}
]
},
"published": "2026-10-01T15:17:31.237",
"references": [
{
"source": "psirt@hcl.com",
"tags": [
"Vendor Advisory"
],
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015"
}
],
"sourceIdentifier": "psirt@hcl.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-319"
}
],
"source": "psirt@hcl.com",
"type": "Secondary"
}
]
}
} | — |
Every claim, by kind
vulnerability
| HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks. zetlyn/cve-nvd · 2026-10-01 | automatable no cvss 7.4 cvss_vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N cwe CWE-319 exploitation none product HCL BigFix Service Management severity HIGH status Analyzed technical_impact total vendor HCL Software | source |
| HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could... zetlyn/cve-ghsa · 2026-10-01 | cvss 7.4 cwe CWE-319 severity high | source |