HCL BigFix Remote Control Server WebUI Content Security Policy Bypass Vulnerability

Vulnerability

A vulnerability exists in HCL BigFix Remote Control Server WebUI in versions through 10.1.0.0442. The issue arises from a misconfigured Content Security Policy (CSP) that fails to establish directives without fallbacks. This flaw enables attackers to circumvent intended security measures and load unauthorized resources.

Impact

Exploitation of this vulnerability allows for bypassing of security restrictions, potentially leading to the loading of unauthorized resources.

Remediation

Users can upgrade to HCL BigFix Remote Control Remote Control 10.1 Fix Pack 5 to address this vulnerability.

Added: May 28, 2026, 3:18 AM
Updated: May 28, 2026, 3:18 AM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
0.2
exploitability
5.8
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.