CVE-2025-0274
BaseFortify
Publication date: 2025-10-16
Last updated on: 2025-10-21
Assigner: HCL Software
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hcltech | bigfix_mobile | to 3.3 (inc) |
| hcltech | bigfix_modern_client_management | to 3.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in HCL BigFix Modern Client Management (MCM) 3.3 and earlier involves improper access control, which allows unauthorized users to access a limited set of endpoint actions and some internal functions that should be restricted.
How can this vulnerability impact me? :
The impact of this vulnerability is that unauthorized users could perform certain endpoint actions or access select internal functions, potentially leading to limited disruption or unauthorized activity on affected systems. However, it does not affect confidentiality or integrity, only availability to a limited extent.