5.3
CVE-2025-0274
- EPSS 0.04%
- Veröffentlicht 16.10.2025 04:56:49
- Zuletzt bearbeitet 21.10.2025 18:21:10
- Quelle psirt@hcl.com
- CVE-Watchlists
- Unerledigt
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hcltech ≫ Bigfix Mobile Version <= 3.3
Hcltech ≫ Bigfix Modern Client Management Version < 3.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.13 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| psirt@hcl.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.