ZeroHour

CVE-2025-0276

CVSS 3.1
6.1 medium
EPSS
<1%p21
Published
()
Modified
Description

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Vendors
hcltech
Products
bigfix mobile, bigfix modern client management
Weakness
CWE-79, CWE-80, CWE-693
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.