HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content.
Metrics
Affected Vendors & Products
References
History
Wed, 06 May 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 06 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields which, when saved to a CSV file, may attempt information exfiltration or other malicious activity when automatically executed by the spreadsheet software. Note that current versions of Excel warn users of untrusted content. | |
| Title | HCL BigFix Service Management (SM) does not adequately sanitize or safely render | |
| Weaknesses | CWE-201 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published:
Updated: 2026-05-06T14:47:34.200Z
Reserved: 2025-04-01T18:46:26.621Z
Link: CVE-2025-31978
Updated: 2026-05-06T14:47:30.934Z
Status : Received
Published: 2026-05-06T15:16:06.207
Modified: 2026-05-06T15:16:06.207
Link: CVE-2025-31978
No data.
OpenCVE Enrichment
Updated: 2026-05-06T16:00:06Z