CVE-2025-0276

MEDIUM

HCL BigFix MCM <3.3 - XSS

Title source: llm

Description

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Scores

CVSS v3 6.5
EPSS 0.0007
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Classification

CWE
CWE-80 CWE-79 CWE-693
Status published

Affected Products (2)

hcltech/bigfix_mobile < 3.3
hcltech/bigfix_modern_client_management < 3.4

Timeline

Published Oct 16, 2025
Tracked Since Feb 18, 2026