HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.7%
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
In short
HCL BigFix Mobile/Modern Client Management allows attackers to send XML commands and enroll devices without needing to log in, potentially compromising device management and control.
Technical detail
The application fails to properly authenticate XML interaction endpoints and device enrollment mechanisms, enabling unauthenticated threat actors to submit malicious XML payloads and register unauthorized devices. This vector bypasses authentication controls and may lead to unauthorized device management, data exfiltration, or lateral movement within the managed environment.
Summary generated and translated by AI from the official description.
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
HCL Software · HCL BigFix Mobile / Modern Client Management