---
cve: "CVE-2026-67171"
severity: "MEDIUM"
cvss: 5.3
epss: "0.2%"
vendor: "HCL Software"
kev: false
exploited: false
published: "2026-10-01 17:17:30"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T06:58:59+02:00"
---

# CVE-2026-67171

> 5.3 MEDIUM

## Beschreibung

HCL BigFix Service Management is affected by an Information Disclosure vulnerability because an exposed API endpoint exposes sensitive internal database information. This information could enable an attacker to facilitate targeted database attacks.

## CNA-Record (Kanon, cvelistV5)

- CNA: **HCL**
- State: PUBLISHED
- Stand: 2026-10-01 16:32:08
- CNA-CVSS: **5.3** (`CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N`)

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## BSI-Hinweise (deutsch)

- [HCL BigFix: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-3707) — _BSI-Einstufung: mittel_
  Ein Angreifer kann mehrere Schwachstellen in HCL BigFix ausnutzen, um Informationen offenzulegen, um Daten zu manipulieren und um einen Cross-Site Scripting Angriff durchzuführen.

## Referenzen

- <https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0134015>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-67171) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
