HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

Project Subscriptions

Vendors Products
Hclsoftware Subscribe
Bigfix Quantum Risk Analyzer Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 28 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Hclsoftware
Hclsoftware bigfix Quantum Risk Analyzer
Vendors & Products Hclsoftware
Hclsoftware bigfix Quantum Risk Analyzer

Thu, 27 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Description HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.
Title HCL BigFix Quantum Risk Analyzer is affected by a stack-based buffer overflow
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 3.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2026-08-27T16:05:13.677Z

Reserved: 2026-01-05T16:08:06.682Z

Link: CVE-2026-21807

cve-icon Vulnrichment

Updated: 2026-08-27T16:04:55.319Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-26T23:17:12.713

Modified: 2026-08-28T16:06:43.297

Link: CVE-2026-21807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T20:32:23Z

Weaknesses