CVE-2021-27780CWE-112
HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
Medium · published May 27, 2022
What it is
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
The record
Technical detail
- CVSS v3.1
- 5.3 · MEDIUM
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00738 · 52.1th percentile
- Weakness
- CWE-112 · Missing XML Validation
- Published
- 2022-05-27T16:15Z
EPSS history
Timeline