---
id: CVE-2025-0277
title: >-
  HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure
  directives within the Content Security Policy (CSP)
summary: >-
  HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure
  directives within the Content Security Policy (CSP).  An attacker could trick
  users into performing actions by not properly restricting the sources of
  scripts and other…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-79
  - CWE-80
  - CWE-693
vendor: hcltech
product: bigfix_mobile
affected:
  - bigfix_mobile <= 3.3
  - bigfix_modern_client_management < 3.4
patched:
  - bigfix_modern_client_management 3.4
published: '2025-10-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-0277'
references:
  - url: >-
      https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0124513
    label: psirt@hcl.com
tags:
  - nvd
epss: 0.00305
epssPercentile: 0.21366
ingestedAt: '2026-10-08T11:31:27.452Z'
---

## Overview

HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP).  An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.

## Affected

- `bigfix_mobile <= 3.3`
- `bigfix_modern_client_management < 3.4`

## Remediation

Upgrade past the affected range:

- `bigfix_modern_client_management 3.4`
