Secure Access prior to version 13.54. Attackers with administrative
access to the console and who have been assigned a certain set of
permissions can bypass those permissions to improperly modify settings.
The attack complexity is low, there are no preexisting attack
requirements; the privileges required are high, and there is no user
interaction required. There is no impact to system confidentiality or
availability, impact to system integrity is high.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16358 | CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. There is no impact to system confidentiality or availability, impact to system integrity is high. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 04 Jun 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Absolute
Absolute secure Access |
|
| CPEs | cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Absolute
Absolute secure Access |
|
| Metrics |
cvssV3_1
|
Thu, 29 May 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
ssvc
|
Wed, 28 May 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. There is no impact to system confidentiality or availability, impact to system integrity is high. | |
| Title | Permissions bypass in the management console of Absolute Secure Access prior to version 13.54 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Absolute
Published:
Updated: 2025-05-28T23:54:02.125Z
Reserved: 2025-03-05T23:12:09.704Z
Link: CVE-2025-27702
Updated: 2025-05-28T23:50:10.902Z
Status : Analyzed
Published: 2025-05-28T21:15:21.307
Modified: 2025-06-04T15:37:13.483
Link: CVE-2025-27702
No data.
OpenCVE Enrichment
No data.
EUVD