6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Description
HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
Basic Information
ID
CVE-2025-0276
Source
HCL
Published
Oct 16, 2025 at 08:25
Affected Product
Vendor
HCL Software
Product
BigFix Modern Client Management
Version
<=3.3
Affected Versions
HCL Software BigFix Modern Client Management <=3.3