CVE-2024-42185
Estado: AplazadaBaja (2.5)—
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N
- Puntuación base: 2.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.13%
- Percentil entre todas las CVEs puntuadas: 2
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-611
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-42185",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-42185",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-23T14:51:43.108292Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 2.5,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "psirt@hcl.com",
"affectedData": [
{
"vendor": "HCL Software",
"product": "BigFix Patch Management Download Plug-ins",
"versions": [
{
"status": "affected",
"version": "1177 and below"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-01-23T03:15:08.860",
"references": [
{
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0118565",
"source": "psirt@hcl.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "psirt@hcl.com",
"description": [
{
"lang": "en",
"value": "CWE-611"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access."
},
{
"lang": "es",
"value": "Los complementos de BigFix Patch Download se ven afectados por un paquete inseguro que es susceptible a ataques de inyección XML. Esto permite que un atacante aproveche esta vulnerabilidad inyectando contenido XML malicioso, lo que puede provocar varios problemas, como la denegación de servicio y el acceso no autorizado."
}
],
"lastModified": "2026-06-17T07:49:00.167",
"sourceIdentifier": "psirt@hcl.com"
}