CVE-2025-31978 Details
Description
HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.
A vulnerability exists in HCL BigFix Service Management (SM) version 23, where the application fails to properly sanitize or securely render spreadsheet files (CSV, XLS, XLSX) before processing or distribution. This oversight could enable an attacker to manipulate data fields in a way that, when the file is opened in spreadsheet software like Excel, could lead to information exfiltration or other malicious activities. Although current versions of Excel provide warnings about untrusted content, this vulnerability could still be exploited.
Users can upgrade to HCL BigFix Service Management (SM) version 27 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0128144 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| hcltech bigfix service management | 23.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | Modified Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 7, 2026 | Initial Analysis | [email protected] |
| May 6, 2026 | New CVE Received | [email protected] |