HCL BigFix Mobile Improper Access Control Vulnerability

Vulnerability

An improper access control vulnerability exists in HCL BigFix Mobile versions through 3.3. This vulnerability allows unauthorized users to access a limited range of endpoint actions, which could potentially lead to access to certain internal functions.

Impact

Exploitation of this vulnerability could allow unauthorized users to access restricted endpoint actions and internal functions, possibly leading to unauthorized changes or access within the application.

Remediation

Users are advised to upgrade to HCL BigFix Mobile version 3.4 or higher.

Added: Oct 16, 2025, 6:17 AM
Updated: Oct 16, 2025, 6:17 AM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
0.6
exploitability
7.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.