CVE 6.5 MEDIUM

HCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)_CVE-2025-0277

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Basic Information

ID CVE-2025-0277
Source HCL
Published Oct 16, 2025 at 08:27

Affected Product

Vendor HCL Software
Product BigFix Mobile
Version <=3.3
Affected Versions HCL Software BigFix Mobile <=3.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.