CVE Vulnerabilities

CVE-2024-23583

Insufficiently Protected Credentials

Published: May 17, 2024 | Modified: Jan 08, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An attacker could potentially intercept credentials via the task manager and perform unauthorized access to the Client Deploy Tool on Windows systems.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Bigfix_platform Hcltech 9.5 (including) 9.5.25 (excluding)
Bigfix_platform Hcltech 10 (including) 10.0.12 (excluding)
Bigfix_platform Hcltech 11.0.1 (including) 11.0.1 (including)

Potential Mitigations

References