---
id: CVE-2025-0276
title: >-
  HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to
  certain insecure directives within the Content Security Policy (CSP)
summary: >-
  HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to
  certain insecure directives within the Content Security Policy (CSP).  An
  attacker could trick users into performing actions by not properly restricting
  the sour…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-79
  - CWE-80
  - CWE-693
vendor: hcltech
product: bigfix_mobile
affected:
  - bigfix_mobile <= 3.3
  - bigfix_modern_client_management < 3.4
patched:
  - bigfix_modern_client_management 3.4
published: '2025-10-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-0276'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124513
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00305
epssPercentile: 0.21367
ingestedAt: '2026-10-08T11:31:27.452Z'
---

## Overview

HCL BigFix Modern Client Management (MCM) 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP).  An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

## Affected

- `bigfix_mobile <= 3.3`
- `bigfix_modern_client_management < 3.4`

## Remediation

Upgrade past the affected range:

- `bigfix_modern_client_management 3.4`
