CVE 4.7 MEDIUM

HCL BigFix Remote Control is vulnerable to an insecure CSP configuration_CVE-2025-59849

4.7 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

Description

Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.

Basic Information

ID CVE-2025-59849
Source HCL
Published Dec 17, 2025 at 20:28
Modified Dec 17, 2025 at 20:45

Affected Product

Vendor HCL Software
Product BigFix Remote Control
Version <= 10.1.0.0326
Affected Versions HCL Software BigFix Remote Control <= 10.1.0.0326

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.