CVE-2025-0275: Hcltech Bigfix Mobile
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
Affected products
- Hcltech Bigfix Mobile: up to and including 3.3
- Hcltech Bigfix Modern Client Management: before 3.4 (fixed in 3.4)
Published 2025-10-16. Last modified 2026-10-08.