HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.
Metrics
Affected Vendors & Products
References
History
Thu, 07 May 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech bigfix Service Management |
|
| CPEs | cpe:2.3:a:hcltech:bigfix_service_management:23.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Hcltech
Hcltech bigfix Service Management |
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content. | |
| Title | HCL BigFix Service Management (SM) does not adequately sanitize or safely render | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2026-05-06T13:48:32.992Z
Updated: 2026-05-06T14:47:34.200Z
Reserved: 2025-04-01T18:46:26.621Z
Link: CVE-2025-31978
Updated: 2026-05-06T14:47:30.934Z
Status : Analyzed
Published: 2026-05-06T15:16:06.207
Modified: 2026-05-07T16:26:10.870
Link: CVE-2025-31978
No data.
ReportizFlow