CVE-2025-0277
⚪ Do wiadomości
Nieprawidłowe dyrektywy w CSP w HCL BigFix Mobile umożliwiają atakującym oszukiwanie użytkowników.
CVSS
6.5
EPSS
0.3%
Exploit
none
Vendor
hcltech
Opis źródłowy (NVD)
HCL BigFix Mobile 3.3 and earlier are vulnerable to certain insecure directives within the Content Security Policy (CSP). An attacker could trick users into performing actions by not properly restricting the sources of scripts and other content.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-10-16 09:15:32 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 11:10:00 UTC |
Referencje