Vulnerabilities > Hcltech > Bigfix OSD Bare Metal Server

DATE CVE VULNERABILITY TITLE RISK
2023-06-22 CVE-2023-28006 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Hcltech Bigfix OSD Bare Metal Server 311.12
The OSD Bare Metal Server uses a cryptographic algorithm that is no longer considered sufficiently secure.
local
low complexity
hcltech CWE-327
7.8
2023-06-22 CVE-2023-28016 Injection vulnerability in Hcltech Bigfix OSD Bare Metal Server 311.12
Host Header Injection vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to supply invalid input to cause the OSD Bare Metal Server to perform a redirect to an attacker-controlled domain.
network
low complexity
hcltech CWE-74
6.1
2023-06-22 CVE-2023-23343 Improper Restriction of Rendered UI Layers or Frames vulnerability in Hcltech Bigfix OSD Bare Metal Server 311.12
A clickjacking vulnerability in the HCL BigFix OSD Bare Metal Server version 311.12 or lower allows attacker to use transparent or opaque layers to trick a user into clicking on a button or link on another page to perform a redirect to an attacker-controlled domain.
network
low complexity
hcltech CWE-1021
6.1