CVE-2026-67105
Received Received - Intake

Insecure Communication in HCL BigFix Service Management

Vulnerability report for CVE-2026-67105, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: HCL Software

Description

HCL BigFix Service Management is affected by an Insecure Communication vulnerability, which could allow an attacker with internal network access to intercept unencrypted HTTP traffic between backend services, enabling the extraction of sensitive data and potential man-in-the-middle (MitM) attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hcl bigfix_service_management *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-319 The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

HCL BigFix Service Management has an Insecure Communication vulnerability where backend services communicate over unencrypted HTTP. This allows attackers with internal network access to intercept traffic, extract sensitive data, or perform man-in-the-middle attacks.

Detection Guidance

Detecting this vulnerability requires monitoring for unencrypted HTTP traffic between backend services. Use network sniffing tools like Wireshark or tcpdump to inspect traffic for plaintext HTTP communications. Check HCL BigFix Service Management logs for any unusual or unencrypted data transmissions.

Impact Analysis

An attacker could steal sensitive data like credentials or session tokens, modify transmitted data, or impersonate services. This could lead to unauthorized access, data breaches, or service disruption.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for encrypted data transmission. Non-compliance could result in fines, legal penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Immediately enforce HTTPS for all communications between backend services. Update HCL BigFix Service Management to the latest secure version. Disable any unencrypted HTTP endpoints and ensure all sensitive data is transmitted over encrypted channels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67105. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart