<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3avmwarefusion/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 14:21:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3avmwarefusion/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Multiple Vulnerabilities in HCL BigFix</title><link>https://feed.craftedsignal.io/briefs/2026-10-hcl-bigfix-vulns/</link><pubDate>Fri, 02 Oct 2026 14:21:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-hcl-bigfix-vulns/</guid><description>HCL BigFix is affected by multiple security vulnerabilities (CVE-2024-22248, CVE-2024-22249, CVE-2024-22250, CVE-2024-22251, CVE-2024-22252) that could allow a remote attacker to conduct cross-site scripting (XSS), disclose sensitive information, or manipulate data.</description><content:encoded><![CDATA[<p>HCL has disclosed multiple vulnerabilities affecting HCL BigFix. These security flaws allow unauthenticated or authenticated attackers to perform unauthorized actions, including the disclosure of sensitive system information, the manipulation of data within the BigFix environment, and the execution of Cross-Site Scripting (XSS) attacks. The affected CVEs are CVE-2024-22248, CVE-2024-22249, CVE-2024-22250, CVE-2024-22251, and CVE-2024-22252. These vulnerabilities could lead to significant compromise of the management infrastructure, as BigFix typically operates with high-level administrative privileges across endpoints. Defenders should review HCL security bulletins to identify the specific patch versions associated with these identifiers and prioritize the remediation of management consoles exposed to internal or external networks.</p>
<h2 id="impact">Impact</h2>
<p>The identified vulnerabilities pose a risk to the integrity and confidentiality of the entire HCL BigFix deployment. If exploited, an attacker could potentially gain unauthorized access to managed assets, exfiltrate sensitive endpoint information, or inject malicious scripts into the BigFix web console to target administrative users.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Review the official HCL BigFix security advisories to determine the affected versions and the corresponding patches for your specific deployment.</li>
<li>Update all HCL BigFix components to the latest patched versions as recommended by the vendor.</li>
<li>Restrict network access to the HCL BigFix Web Console and management interfaces to trusted administrative subnets only.</li>
<li>Monitor web server logs for suspicious activity involving unusual parameters or attempts to inject script-based payloads into the application interface.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>vulnerability</category><category>web-application</category><category>hcl-bigfix</category></item></channel></rss>