← Vulnerability feed

Vulnerability record · CVE-2025-52613 · published 6 May 2026

CVE-2025-52613: Hcltech bigfix service management information exposure vulnerability

Hcltech · Bigfix Service Management

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

8.8 CVSS 3.1 High EPSS 0.23% · top 87.2% CWE-200 · Information exposure
8.8CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses, potentially increasing the risk of exploitation and unauthorized access.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-52613 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-31973Hcltech bigfix service management vulnerabilityHCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images m…EPSS 0.18%8.3CVE-2024-30151Hcltech bigfix service management sensitive information in log file vulnerabilityHCL BigFix Service Management (SX) is affected by a Broken Access Control vulnerability leading to privilege escalation. This could allow unauthorize…EPSS 0.25%8.2CVE-2025-31958Hcltech bigfix service management http request smuggling vulnerabilityHCL BigFix Service Management is susceptible to HTTP Request Smuggling.  HTTP request smuggling vulnerabilities arise when websites route HTTP reques…EPSS 0.18%7.5CVE-2025-31976Hcltech bigfix service management information exposure vulnerabilityHCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, int…EPSS 0.16%7.2CVE-2025-31974Hcltech bigfix service management insecure default initialization vulnerabilityHCL BigFix Service Management (SM) is susceptible to a Root File System Not Mounted as Read-Only. An improperly configured root file system may allow…EPSS 0.18%6.5CVE-2025-31985Hcltech bigfix service management information exposure vulnerabilityHCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This coul…EPSS 0.16%6.5CVE-2025-31982Hcltech bigfix service management information exposure vulnerabilityHCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an incre…EPSS 0.15%6.5CVE-2025-31972Hcltech bigfix service management cleartext transmission vulnerabilityHCL BigFix SM is affected by a Sensitive Information Exposure vulnerability where internal connections do not use TLS encryption which could allow an…EPSS 0.09%

Source: NIST National Vulnerability Database (record CVE-2025-52613), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.