CVE-2021-27783: HCL BigFix Mobile / Modern Client Management is vulnerable to sensitive information exposure
Published May 25, 2022
·Updated
User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
Affected Software
4 affected components
hcltech Bigfix Mobile=2.0
hcltech Bigfix Mobile=2.1
hcltech Bigfix Modern Client Management=2.0
hcltech Bigfix Modern Client Management=2.1
Event History
May 25, 2022
CVE Published
via MITRE·03:20 PM
Data Sourced
via MITRE·03:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27783?
CVE-2021-27783 is a vulnerability that allows user-generated PPKG files for Bulk Enroll to expose unencrypted sensitive information.
2
What software is affected by CVE-2021-27783?
The affected software includes Hcltech Bigfix Mobile versions 2.0 and 2.1, as well as Hcltech Bigfix Modern Client Management versions 2.0 and 2.1.
3
What is the severity level of CVE-2021-27783?
CVE-2021-27783 has a severity level of medium.
4
How can CVE-2021-27783 be exploited?
CVE-2021-27783 can be exploited by using user-generated PPKG files for Bulk Enroll that contain unencrypted sensitive information.
5
What is the suggested fix for CVE-2021-27783?
To fix CVE-2021-27783, update to the latest version of Hcltech Bigfix Mobile or Hcltech Bigfix Modern Client Management software.