HCL BigFix IVR
cpe:2.3:h:hcltech:legacy_ivr:*:*:*:*:*:*:*, +1 more
- 4.2
A vulnerability exists in HCL BigFix IVR version 4.2 due to improper service binding in internal components. This flaw allows a privileged attacker to disrupt service availability by exposing administrative services to external network interfaces, rather than keeping them confined to the local authentication interface.
Exploitation of this vulnerability could lead to a denial-of-service condition by disrupting the availability of services exposed to external network interfaces.
Users are advised to upgrade to HCL BigFix IVR version 4.2.1.0 or later. Instructions for upgrading are available in the BigFix Console under the 'Fixlets and Tasks' node.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.