CVE-2025-27703

Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/05/2025
Last modified:
04/06/2025

Description

CVE-2025-27703 is a privilege escalation vulnerability in the management<br /> console of Absolute Secure Access prior to version 13.54. Attackers <br /> with administrative access to a specific subset of privileged features <br /> in the console can elevate their permissions to access additional <br /> features in the console. The attack complexity is low, there are no <br /> preexisting attack requirements; the privileges required are high, and <br /> there is no user interaction required. The impact to system <br /> confidentiality is low, the impact to system integrity is high and the <br /> impact to system availability is low.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* 13.54 (excluding)