← Back

CVE-2025-0277

nvd nist
Published: Oct 16, 2025Modified: Oct 21, 2025

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Affected (2)

2 products
Bigfix Mobile
Bigfix Modern Client Management
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.3
Before 3.4

Timeline

No history available yet.