VulnerabilityAnalyzed
CVE-2025-31959
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images.
LOW 3.5EPSS 0.14%
Does this matter?
Lower severity and a low EPSS score (0.14%). Track it; it rarely justifies an emergency change on its own.
Description
HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentionally shared. .
- CVSS 3.1
- 3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.14% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1230
- Affected
- hcltech/bigfix service management
- Source
- psirt@hcl.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.