6.9

CVE-2025-27702

Permissions bypass in the management console of Absolute Secure Access prior to version 13.54

CVE-2025-27702 is a vulnerability in the management console of Absolute 
Secure Access prior to version 13.54. Attackers with administrative 
access to the console and who have been assigned a certain set of 
permissions can bypass those permissions to improperly modify settings. 
The attack complexity is low, there are no preexisting attack 
requirements; the privileges required are high, and there is no user 
interaction required. There is no impact to system confidentiality or 
availability, impact to system integrity is high.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AbsoluteSecure Access Version < 13.54
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.168
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.9 1.2 3.6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
SecurityResponse@netmotionsoftware.com 6.9 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://www.absolute.com/platform/vulnerability-archive/cve-2025-27702
Vendor Advisory