Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-27703

Опубликовано: 28 мая 2025
Источник: nvd
CVSS3: 6
EPSS Низкий

Описание

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
Версия до 13.54 (исключая)

EPSS

Процентиль: 15%
0.00049
Низкий

6 Medium

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 6
github
8 месяцев назад

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

EPSS

Процентиль: 15%
0.00049
Низкий

6 Medium

CVSS3

Дефекты

CWE-281