Content Security Policy Vulnerabilities in HCL BigFix Modern Client Management
CVE-2025-0276
6.5MEDIUM
What is CVE-2025-0276?
HCL BigFix Modern Client Management versions 3.3 and earlier include a vulnerability that arises from insecure directives in the Content Security Policy (CSP). This issue allows an attacker to manipulate the policy, potentially tricking users into executing unintended actions by failing to adequately restrict the sources of scripts and other content. Organizations using affected versions should assess their risk and implement recommended security measures.
Affected Version(s)
BigFix Modern Client Management <=3.3