HCL BigFix Platform is affected by insecure permissions on private cryptographic keys. The private cryptographic keys located on a Windows host machine might be subject to overly permissive file system permissions.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Hcltech Bigfix_Platform
cpe:2.3:a:hcltech:bigfix_platform:*:*:*:*:*:*:*:*
|
11.0.0
|
<= 11.0.5
|