216.73.217.22

CVE-2025-27703

· Published 28/05/2025 21:15 · Modified 29/05/2025 14:29

Labels: CVE-2025-27703 2025-05-28CVE-2025-27703CWE-281[email protected]

Essential information

Published
28/05/2025 21:15
Modified
29/05/2025 14:29
Author
Creator
CVSS
7.0 HIGH (v3) 7.0 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack complexity is low, there are no preexisting attack requirements; the privileges required are high, and there is no user interaction required. The impact to system confidentiality is low, the impact to system integrity is high and the impact to system availability is low.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
absolute / secure access cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*

References