CVE-2025-0277

MEDIUM

HCL BigFix Mobile <3.3 - XSS

Title source: llm
STIX 2.1

Description

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

Scores

CVSS v3 6.5
EPSS 0.0002
EPSS Percentile 6.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-80 CWE-79 CWE-693
Status published
Products (2)
hcltech/bigfix_mobile < 3.3
hcltech/bigfix_modern_client_management < 3.4
Published Oct 16, 2025
Tracked Since Feb 18, 2026