Description
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Published: 2025-12-17
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Jan 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltechsw
Hcltechsw hcl Devops Deploy
Hcltechsw hcl Launch
CPEs cpe:2.3:a:hcltechsw:hcl_devops_deploy:*:*:*:*:*:*:*:*
cpe:2.3:a:hcltechsw:hcl_launch:*:*:*:*:*:*:*:*
Vendors & Products Hcltechsw
Hcltechsw hcl Devops Deploy
Hcltechsw hcl Launch

Thu, 18 Dec 2025 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Hcltech
Hcltech bigfix Remote Control
Vendors & Products Hcltech
Hcltech bigfix Remote Control

Wed, 17 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 17 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
Title HCL BigFix Remote Control is vulnerable to an insecure CSP configuration
Weaknesses CWE-1021
CWE-693
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Hcltech Bigfix Remote Control
Hcltechsw Hcl Devops Deploy Hcl Launch
cve-icon MITRE

Status: PUBLISHED

Assigner: HCL

Published:

Updated: 2025-12-17T20:45:21.930Z

Reserved: 2025-09-22T14:59:58.051Z

Link: CVE-2025-59849

cve-icon Vulnrichment

Updated: 2025-12-17T20:43:37.779Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-17T21:16:14.873

Modified: 2026-01-06T19:54:47.700

Link: CVE-2025-59849

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-18T09:56:02Z

Weaknesses