HCL BigFix Modern Client Management Insecure Content Security Policy Vulnerability

Vulnerability

A vulnerability exists in HCL BigFix Modern Client Management (MCM) versions through 3.3, due to an insecure Content Security Policy (CSP) that fails to adequately restrict the sources of scripts and other content. This weakness could allow an attacker to manipulate users into taking unintended actions.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed by users, potentially allowing attackers to manipulate user behavior or access sensitive information.

Remediation

Users can upgrade to HCL BigFix MCM 3.4 or higher through the MCM WebUI.

Added: Oct 16, 2025, 9:24 AM
Updated: Oct 16, 2025, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
1.7
exploitability
6.0
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.