Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3vv-fgcp-2m26

Опубликовано: 28 мая 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7
CVSS3: 6

Описание

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

EPSS

Процентиль: 15%
0.00049
Низкий

7 High

CVSS4

6 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 6
nvd
9 месяцев назад

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

EPSS

Процентиль: 15%
0.00049
Низкий

7 High

CVSS4

6 Medium

CVSS3

Дефекты

CWE-281