Aller au contenu

Fiche vulnérabilité

CVE-2022-38658 : faille élevée hcltech bigfix server automation (CVSS 7.5)

Description

BigFix deployments that have installed the Notification Service on Windows are susceptible to disclosing SMTP BigFix operator's sensitive data in clear text. Operators who use Notification Service related content from BES Support are at risk of leaving their SMTP sensitive data exposed.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
24 déc. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • hcltech bigfix server automation

Références

Rechercher une autre vulnérabilité dans la base CVE