6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Description
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
Basic Information
ID
CVE-2025-0277
Source
HCL
Published
Oct 16, 2025 at 08:27
Affected Product
Vendor
HCL Software
Product
BigFix Mobile
Version
<=3.3
Affected Versions
HCL Software BigFix Mobile <=3.3