CVE 5.3 MEDIUM

Elevation of privilege vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.56_CVE-2025-49084

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:H/SI:L/SA:H

Description

CVE-2025-49084 is a vulnerability in the management console
of Absolute Secure Access prior to version 13.56. Attackers with administrative
access can overwrite policy rules without the requisite permissions. The attack
complexity is low, attack requirements are present, privileges required are
high and no user interaction is required. There is no impact to
confidentiality, the impact to integrity is low, and there is no impact to
availability. The impact to confidentiality and availability of subsequent systems
is high and the impact to the integrity of subsequent systems is low.

Basic Information

ID CVE-2025-49084
Source Absolute
Published Jul 30, 2025 at 23:36
Modified Jul 31, 2025 at 13:33

Affected Product

Vendor Absolutee Security
Product Secure Access
Affected Versions Absolutee Security Secure Access 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.