← back
CVE-2024-42213

HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment

CVSS 5.3 MEDIUMEPSS 0.3%CWE-531
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.3EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 May 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
HCL BigFix Compliance is affected by inclusion of temporary files left in the production environment. An attacker might gain access to these files by indexing or retrieved via predictable URLs or misconfigured permissions, leading to information disclosure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →