CVE-2025-54085

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
31/07/2025
Last modified:
05/08/2025

Description

CVE-2025-54085 is a vulnerability in the management console<br /> of Absolute Secure Access prior to version 13.56. Attackers with administrative<br /> access to the console and who have been assigned a certain set of permissions<br /> can bypass those permissions to improperly read or change other settings. The<br /> attack complexity is low, there are no preexisting attack requirements; the<br /> privileges required are high, and there is no user interaction required. The<br /> impact to system confidentiality and integrity is low, there is no impact to<br /> system availability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.56 (excluding)