CVE-2025-0274: Hcltech Bigfix Mobile
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
HCL BigFix Modern Client Management (MCM) 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
Affected products
- Hcltech Bigfix Mobile: up to and including 3.3
- Hcltech Bigfix Modern Client Management: before 3.4 (fixed in 3.4)
Published 2025-10-16. Last modified 2026-10-08.