First published: Mon May 09 2022(Updated: )
The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Mobile | >=1.0<2.1 | |
Hcltech Modern Client Management | >=1.0<2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27780 is a vulnerability that allows Un-Auth XML interaction and unauthenticated device enrollment in vulnerable software.
The software affected by CVE-2021-27780 includes Hcltech Bigfix Mobile (versions 1.0 - 2.1) and Hcltech Modern Client Management (versions 1.0 - 2.1).
The severity of CVE-2021-27780 is medium with a CVSS score of 5.3.
To fix CVE-2021-27780, it is recommended to update the affected software to a version that is not vulnerable.
You can find more information about CVE-2021-27780 at the following link: [link](https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0098028)