CVE-2025-49084

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
31/07/2025
Last modified:
05/08/2025

Description

CVE-2025-49084 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access can overwrite policy rules without the requisite permissions. The attack<br /> complexity is low, attack requirements are present, privileges required are<br /> high and no user interaction is required. There is no impact to<br /> confidentiality, the impact to integrity is low, and there is no impact to<br /> availability. The impact to confidentiality and availability of subsequent systems<br /> is high and the impact to the integrity of subsequent systems is low.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.56 (excluding)