CVE-2025-54087

Severity CVSS v4.0:
LOW
Type:
CWE-918 Server-Side Request Forgery (SSRF)
Publication date:
02/10/2025
Last modified:
16/10/2025

Description

CVE-2025-54087 is a server-side request forgery<br /> vulnerability in Secure Access prior to version 14.10. Attackers with<br /> administrative privileges can publish a crafted test HTTP request originating<br /> from the Secure Access server. The attack complexity is high, there are no<br /> attack requirements, and user interaction is required. There is no direct<br /> impact to confidentiality, integrity, or availability. There is a low severity<br /> subsequent system impact to integrity.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 14.10 (excluding)