CVE-2025-49082

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
31/07/2025
Last modified:
05/08/2025

Description

CVE-2025-49082 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access to the console and who have been assigned a certain set of permissions<br /> can bypass those permissions to improperly read other settings. The attack<br /> complexity is low, there are no preexisting attack requirements; the privileges<br /> required are high, and there is no user interaction required. The impact to<br /> system confidentiality is low, there is no impact to system availability or<br /> integrity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.56 (excluding)