Known Vulnerabilities for Bigfix Mobile by Hcltech
Listed below are 6 of the newest known vulnerabilities associated with "Bigfix Mobile" by "Hcltech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-28014 json | HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could inject malicious scripts in... | 5.4 - MEDIUM | 2023-07-27 | 2023-08-03 |
| CVE-2023-28012 json | HCL BigFix Mobile is vulnerable to a command injection attack. An authenticated attacker could run arbitrary shell commands o... | 8.8 - HIGH | 2023-07-27 | 2023-08-03 |
| CVE-2021-27783 json | User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed. | 6.5 - MEDIUM | 2022-05-25 | 2022-06-07 |
| CVE-2021-27782 json | HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked out for... | 7.5 - HIGH | 2023-01-20 | 2023-11-07 |
| CVE-2021-27781 json | The Master operator may be able to embed script tag in HTML with alert pop-up display cookie. | 4.8 - MEDIUM | 2022-05-27 | 2022-06-08 |
| CVE-2021-27780 json | The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment. | 5.3 - MEDIUM | 2022-05-27 | 2022-06-08 |