CVE-2025-27703
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
28/05/2025
Last modified:
04/06/2025
Description
CVE-2025-27703 is a privilege escalation vulnerability in the management<br />
console of Absolute Secure Access prior to version 13.54. Attackers <br />
with administrative access to a specific subset of privileged features <br />
in the console can elevate their permissions to access additional <br />
features in the console. The attack complexity is low, there are no <br />
preexisting attack requirements; the privileges required are high, and <br />
there is no user interaction required. The impact to system <br />
confidentiality is low, the impact to system integrity is high and the <br />
impact to system availability is low.
Impact
Base Score 4.0
7.00
Severity 4.0
HIGH
Base Score 3.x
6.00
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | 13.54 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



