CVE 6.5 MEDIUM

HCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)_CVE-2025-0276

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Description

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Basic Information

ID CVE-2025-0276
Source HCL
Published Oct 16, 2025 at 08:25

Affected Product

Vendor HCL Software
Product BigFix Modern Client Management
Version <=3.3
Affected Versions HCL Software BigFix Modern Client Management <=3.3

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.