PT-2025-42440 · Hcl · Hcl Bigfix Mobile / Modern Client Management
Published
2025-10-16
·
Updated
2025-10-16
·
CVE-2025-0276
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
HCL BigFix Modern Client Management versions 3.3 and earlier
Description
The software contains insecure directives within the Content Security Policy (CSP). This could allow an attacker to trick users into performing actions by improperly restricting the sources of scripts and other content.
Recommendations
Update to a newer version than 3.3 to address the issue.
Fix
Protection Mechanism Failure
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hcl Bigfix Mobile / Modern Client Management