CVE-2025-49083

Severity CVSS v4.0:
HIGH
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
31/07/2025
Last modified:
05/08/2025

Description

CVE-2025-49083 is a vulnerability in the management console<br /> of Absolute Secure Access after version 12.00 and prior to version 13.56.<br /> Attackers with administrative access to the console can cause unsafe content to<br /> be deserialized and executed in the security context of the console. The attack<br /> complexity is low and there are no attack requirements. Privileges required are<br /> high and there is no user interaction required. The impact to confidentiality<br /> is low, impact to integrity is high and there is no impact to availability. The<br /> impact to the confidentiality and integrity of subsequent systems is low and<br /> there is no subsequent system impact to availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 12.00 (including) 13.56 (excluding)