← Back

CVE-2025-0276

nvd nist
Published: Oct 16, 2025Modified: Oct 21, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Affected (2)

2 products
Bigfix Mobile
Bigfix Modern Client Management
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.3
Before 3.4

Timeline

No history available yet.