CVE-2021-27780: HCL BigFix Mobile / Modern Client Management is vulnerable to unauthenticated XML interaction
Published May 27, 2022
·Updated
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Affected Software
2 affected components
hcltech Bigfix Mobile>=1.0<2.1
hcltech Modern Client Management>=1.0<2.1
Event History
May 27, 2022
CVE Published
via MITRE·04:15 PM
Data Sourced
via MITRE·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27780?
CVE-2021-27780 is a vulnerability that allows Un-Auth XML interaction and unauthenticated device enrollment in vulnerable software.
2
Which software is affected by CVE-2021-27780?
The software affected by CVE-2021-27780 includes Hcltech Bigfix Mobile (versions 1.0 - 2.1) and Hcltech Modern Client Management (versions 1.0 - 2.1).
3
What is the severity of CVE-2021-27780?
The severity of CVE-2021-27780 is medium with a CVSS score of 5.3.
4
How can I fix CVE-2021-27780?
To fix CVE-2021-27780, it is recommended to update the affected software to a version that is not vulnerable.
5
Where can I find more information about CVE-2021-27780?
You can find more information about CVE-2021-27780 at the following link: [link](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028)