CVE-2025-54085

CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality and integrity is low, there is no impact to system availability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

History

05 Aug 2025, 20:03

Type Values Removed Values Added
First Time Absolute
Absolute secure Access
CPE cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 3.8
References () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54085 - () https://www.absolute.com/platform/security-information/vulnerability-archive/cve-2025-54085 - Vendor Advisory

31 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-276
Summary
  • (es) CVE-2025-54085 es una vulnerabilidad en la consola de administración de Absolute Secure Access anterior a la versión 13.56. Los atacantes con acceso administrativo a la consola y con ciertos permisos asignados pueden eludirlos para leer o modificar incorrectamente otras configuraciones. La complejidad del ataque es baja, no existen requisitos previos; se requieren privilegios altos y no se requiere interacción del usuario. El impacto en la confidencialidad e integridad del sistema es bajo y no afecta a su disponibilidad.

31 Jul 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-31 00:15

Updated : 2025-08-05 20:03


NVD link : CVE-2025-54085

Mitre link : CVE-2025-54085

CVE.ORG link : CVE-2025-54085


JSON object : View

Products Affected

absolute

  • secure_access
CWE
CWE-276

Incorrect Default Permissions