CVE-2025-49083
Severity CVSS v4.0:
HIGH
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
31/07/2025
Last modified:
05/08/2025
Description
CVE-2025-49083 is a vulnerability in the management console<br />
of Absolute Secure Access after version 12.00 and prior to version 13.56.<br />
Attackers with administrative access to the console can cause unsafe content to<br />
be deserialized and executed in the security context of the console. The attack<br />
complexity is low and there are no attack requirements. Privileges required are<br />
high and there is no user interaction required. The impact to confidentiality<br />
is low, impact to integrity is high and there is no impact to availability. The<br />
impact to the confidentiality and integrity of subsequent systems is low and<br />
there is no subsequent system impact to availability.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | 12.00 (including) | 13.56 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



