CVE-2025-0275 is an improper access control vulnerability affecting HCL BigFix Mobile 3.3 and earlier, as well as HCL BigFix Modern Client Management. This flaw allows authenticated but unauthorized users to access a limited set of endpoint actions, potentially exposing select internal functions. Rated as Medium severity (CVSS 4.3), the vulnerability has a network attack vector with low attack complexity, requiring low privileges and no user interaction. The potential impact is limited to low confidentiality, with no integrity or availability impact. Currently, there is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3CPE matchmatch criteria | cpe:2.3:a:hcltech:bigfix_mobile:*:*:*:*:*:*:*:* | ||
< 3.4CPE matchmatch criteria | cpe:2.3:a:hcltech:bigfix_modern_client_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.