CVE-2025-54087
Severity CVSS v4.0:
LOW
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
02/10/2025
Last modified:
16/10/2025
Description
CVE-2025-54087 is a server-side request forgery<br />
vulnerability in Secure Access prior to version 14.10. Attackers with<br />
administrative privileges can publish a crafted test HTTP request originating<br />
from the Secure Access server. The attack complexity is high, there are no<br />
attack requirements, and user interaction is required. There is no direct<br />
impact to confidentiality, integrity, or availability. There is a low severity<br />
subsequent system impact to integrity.
Impact
Base Score 4.0
1.80
Severity 4.0
LOW
Base Score 3.x
2.60
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | 14.10 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



