HCL BigFix Modern Client Management
cpe:2.3:a:hcltech:bigfix_modern_client_management:*:*:*:*:*:*:*
- <= 3.3
A vulnerability exists in HCL BigFix Modern Client Management (MCM) versions through 3.3, due to an insecure Content Security Policy (CSP) that fails to adequately restrict the sources of scripts and other content. This weakness could allow an attacker to manipulate users into taking unintended actions.
Exploitation of this vulnerability could lead to unauthorized actions being performed by users, potentially allowing attackers to manipulate user behavior or access sensitive information.
Users can upgrade to HCL BigFix MCM 3.4 or higher through the MCM WebUI.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.