First published: Thu May 19 2022(Updated: )
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Credit: psirt@hcl.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hcltech Bigfix Mobile | =2.0 | |
Hcltech Bigfix Mobile | =2.1 | |
Hcltech Bigfix Modern Client Management | =2.0 | |
Hcltech Bigfix Modern Client Management | =2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27783 is a vulnerability that allows user-generated PPKG files for Bulk Enroll to expose unencrypted sensitive information.
The affected software includes Hcltech Bigfix Mobile versions 2.0 and 2.1, as well as Hcltech Bigfix Modern Client Management versions 2.0 and 2.1.
CVE-2021-27783 has a severity level of medium.
CVE-2021-27783 can be exploited by using user-generated PPKG files for Bulk Enroll that contain unencrypted sensitive information.
To fix CVE-2021-27783, update to the latest version of Hcltech Bigfix Mobile or Hcltech Bigfix Modern Client Management software.